CVE-2023-25188
MEDIUMNokia Asika Airscale Firmware - Origin Validation Error
Title source: ruleDescription
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level.
Scores
CVSS v3
5.1
EPSS
0.0003
EPSS Percentile
9.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H
Classification
CWE
CWE-269
CWE-346
Status
published
Affected Products (5)
nokia/asika_airscale_firmware
nokia/asika_airscale_firmware
nokia/asika_airscale_firmware
nokia/asika_airscale_firmware
nokia/asika_airscale_firmware
Timeline
Published
Jun 16, 2023
Tracked Since
Feb 18, 2026