CVE-2025-24330 OAM service path traversal issue caused by a crafted SOAP message PlanId field within the RAN management network

Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path trave ...

Continue Reading
CVE-2025-24329 OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management network

Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path trav ...

Continue Reading
CVE-2025-24335 SOAP message input validation fault could in theory cause OAM service resource exhaustion

Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the S ...

Continue Reading
CVE-2025-24330 OAM service path traversal issue caused by a crafted SOAP message PlanId field within the RAN management network

Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path trave ...

Continue Reading
CVE-2025-24329 OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management network

Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path trav ...

Continue Reading
Oracle Linux 10 : php (ELSA-2025-7489)

The remote Oracle Linux 10 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2025-7489 advisory. [8.3.19-1] - rebase to 8.3.19 Tenable has extracted ...

Continue Reading
CVE-2024-51983

An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. ...

Continue Reading
CVE-2024-51981

An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that can be leveraged to perform HTTP request smuggling. This SSRF leverages the WS-Ad ...

Continue Reading

Back to Main

Subscribe for the latest news: