CVE-2022-2484
Last modified
CVE-2022-2484 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs. . EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nokia | Asik Airscale 474021a.101 Firmware | All versions |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2484?
How severe is CVE-2022-2484?
How do I fix CVE-2022-2484?
Are you affected by CVE-2022-2484?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
