The OAM service component restarts automatically after the stack overflow without causing a base station restart or network service degradation, and without leaving any permanent impact on the Nokia Single RAN baseband OAM service.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19693 | Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. The OAM service component restarts automatically after the stack overflow without causing a base station restart or network service degradation, and without leaving any permanent impact on the Nokia Single RAN baseband OAM service. |
Wed, 02 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 | |
| Metrics |
cvssV3_1
|
Wed, 02 Jul 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. The OAM service component restarts automatically after the stack overflow without causing a base station restart or network service degradation, and without leaving any permanent impact on the Nokia Single RAN baseband OAM service. | |
| Title | OAM service stack overflow caused by crafted SOAP message within the MNO internal RAN management network | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Nokia
Published:
Updated: 2025-07-02T13:45:17.927Z
Reserved: 2025-01-20T05:33:25.523Z
Link: CVE-2025-24328
Updated: 2025-07-02T13:42:48.640Z
Status : Deferred
Published: 2025-07-02T08:15:21.477
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24328
No data.
OpenCVE Enrichment
No data.
EUVD