CVE-2023-25188
MEDIUMNOKIA Airscale ASIKA Single RAN < 21B - Unauthenticated Privilege Escalation via AaShell Diagnostic Tool
Title source: llmDescription
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level.
References (2)
Core 2
Core References
Product
https://Nokia.com
Scores
CVSS v3
5.1
EPSS
0.0010
EPSS Percentile
1.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-269
CWE-346
Status
published
Products (5)
nokia/asika_airscale_firmware
19b
nokia/asika_airscale_firmware
20a
nokia/asika_airscale_firmware
20b
nokia/asika_airscale_firmware
20c
nokia/asika_airscale_firmware
21a
Published
Jun 16, 2023
Tracked Since
Feb 18, 2026