Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19725 | Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue. |
Wed, 02 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Wed, 02 Jul 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later. Beginning with release 24R1-SR 1.0 MP, the OAM service software utilizes libarchive APIs with security options enabled, effectively mitigating the reported path traversal issue. | |
| Title | OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management network | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Nokia
Published:
Updated: 2025-07-02T13:38:28.621Z
Reserved: 2025-01-20T05:33:25.523Z
Link: CVE-2025-24329
Updated: 2025-07-02T13:36:51.964Z
Status : Deferred
Published: 2025-07-02T09:15:24.390
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24329
No data.
OpenCVE Enrichment
No data.
EUVD