CVE-2025-24329 - CVE House
Back to Database
Status published Unknown CVE-2025-24329

OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management network

Vulnerability Description

Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24329

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Nokia Single RAN
Vulnerable Versions:
All releases prior to 24R1-SR 1.0 MP, 24R1-SR 1.0 MP and later

Timeline

Official Publish: July 2nd, 2025
Last Modified: July 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.