CVE-2025-24332
Authenticated admin user can connect baseband internally from one board to another without needing to re-authentication

Public disclosure

02-07-2025

Last updated

02-07-2025

Vulnerability type

Lack of admin user re-authentication when authenticated admin connects baseband internally between the physical boards

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS score

7.1

Description

Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. The baseband does not re-authenticate the user when they connect from the baseband system board to the baseband capacity boards using the internal bsoc SSH service, which is available only internally within the baseband and through the internal backplane between the boards. The bsoc SSH allows login from one board to another via the baseband internal backplane using an SSH private key present on the baseband system board.

This bsoc SSH capability was previously considered an administrative functionality but has now been restricted to be available only to baseband root-privileged administrators. This restriction mitigates the possibility of misuse with lower-level privileges (e.g., from baseband software images). This mitigation is included starting from release 23R4-SR 3.0 MP and later.

This vulnerability is not exploitable from outside the Mobile Network Operator (MNO) internal architecture, such as from mobile network user devices (UEs), roaming networks, or the Internet. The reported issue is only accessible to an authenticated Single RAN base station administrative user within the MNO internal Radio Access Network (RAN) management network, in software versions earlier than release 23R4-SR 3.0 MP.

No practical exploit or misuse - other than authenticated admin user capability to connect baseband internally from one board to another without user re-authentication - has been detected for this issue.

Affected products and versions

Product

Versions

Nokia Single RAN AirScale (Flexi Multiradio is not affected)

All the releases prior to 23R4-SR 3.0 MP

Mitigation plan

The fix has been included starting from 23R4-SR 3.0 MP.

Acknowledgements

  • Guillaume Teissier (P1 Security France)
  • Laurent Ghigonis (P1 Security France) 
  • Radu Balaci (Bell Mobility Canada)
  • Meghna Patel (Bell Mobility Canada)

References

Change history : Initial version is published on 02-07-2025