2
CVE-2025-24335 - SOAP message input validation fault could in theory cause OAM service resource exhaustion
Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service. No practical exploit has been detected for this flaw. However, theβ¦
3.3
CVE-2025-24334 - The Nokia Single RAN baseband reveals its software version through the MNO internal RAN management β¦
The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release version by sending a specific HTTP POST request through the Mobile Network Operator (MNO) internal RAN management network.
6.4
CVE-2025-24333 - Administrative user shell input validation fault
Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added tβ¦
7.1
CVE-2025-24332 - Authenticated admin user can connect baseband internally from one board to another without needing β¦
Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. The baseband does not re-authenticate the user when they connect from the baseband system board to the baseband capacity boards β¦
6.4
CVE-2025-24331 - Nokia Single RAN baseband OAM service extensive capabilities
The Single RAN baseband OAM service is intended to run as an unprivileged service. However, it initially starts with root privileges and assigns certain capabilities before dropping to an unprivileged level. The capabilities retained from the root period are considered extensive after the privilegeβ¦
6.4
CVE-2025-24330 - OAM service path traversal issue caused by a crafted SOAP message PlanId field within the RAN managβ¦
Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has beβ¦
6.4
CVE-2025-24329 - OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN manaβ¦
Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has bβ¦
4.2
CVE-2025-24328 - OAM service stack overflow caused by crafted SOAP message within the MNO internal RAN management neβ¦
Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected β¦
9.8
CVE-2024-13786 - Education Center | LMS & Online Courses WordPress Theme <= 3.6.10 - PHP Object Injection
The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted input in the 'themerex_callback_view_more_posts' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP β¦
5.5
CVE-2025-6017 - Rhacm: users with clusterreader role can see credentials from managed-clusters
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to aβ¦