CVE-2023-25186: Path Traversal
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband unit diagnostic tool AaShell (which is by default disabled) provides access to the BTS baseband unit internal filesystem from the mobile network solution internal BTS management network.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25186?
CVE-2023-25186 is a vulnerability found in NOKIA Airscale ASIKA Single RAN devices before 21B, which allows directory path traversal in the Nokia BTS baseband unit diagnostic tool.
How severe is CVE-2023-25186?
CVE-2023-25186 has a severity rating of 2.8, considered medium.
What software versions are affected by CVE-2023-25186?
CVE-2023-25186 affects NOKIA Airscale ASIKA Single RAN devices with firmware versions 19b, 20a, 20b, 20c, and 21a.
What is the CWE ID for CVE-2023-25186?
The CWE ID for CVE-2023-25186 is CWE-22.
Where can I find more information about CVE-2023-25186?
You can find more information about CVE-2023-25186 on the official Nokia website and their product security advisory page.