CVE-2022-2483
Last modified
CVE-2022-2483 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device. . EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nokia | Asik Airscale 474021a.102 Firmware | All versions |
| Nokia | Asik Airscale 474021a.101 Firmware | All versions |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2483?
How severe is CVE-2022-2483?
How do I fix CVE-2022-2483?
Are you affected by CVE-2022-2483?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
