CVE-2023-25187 - CVE House
Back to Database
Status published Medium CVE-2023-25187

An issue was discovered on NOKIA Airscale ASIKA Single RAN...

Vulnerability Description

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS network SSH server (disabled by default) continues to apply the default SSH public/private key values. These keys don't give access to BTS, because service user authentication is username/password-based on top of SSH. Nokia factory installed default SSH keys are meant to be changed from operator-specific values during the BTS deployment commissioning phase. However, before the 21B release, BTS commissioning manuals did not provide instructions to change default SSH keys (to BTS operator-specific values). This leads to a possibility for malicious operations staff (inside a CSP network) to attempt MITM exploitation of BTS service user access, during the moments that SSH is enabled for Nokia service personnel to perform troubleshooting activities.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-25187

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Unknown
Vulnerable Versions:
Unknown

Timeline

Official Publish: June 16th, 2023
Last Modified: December 12th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AC:H/AV:L/A:H/C:H/I:H/PR:H/S:U/UI:R

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.