CVE-2025-24334
BaseFortify
Publication date: 2025-07-02
Last updated on: 2025-07-03
Assigner: Nokia
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-497 | The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows an attacker to obtain the exact software release version of Nokia Single RAN baseband software (versions earlier than 23R2-SR 1.0 MP) by sending a specific HTTP POST request through the Mobile Network Operator internal RAN management network.
How can this vulnerability impact me? :
The impact of this vulnerability is that an attacker with access to the Mobile Network Operator internal RAN management network can discover the exact software version running on the Nokia Single RAN baseband. This information could potentially be used to identify known vulnerabilities or weaknesses associated with that software version, aiding further attacks.