CVE-2022-2483 Vulnerability Details

  /     /     /  

CVE-2022-2483 Metadata Quick Info

CVE Published: 06/01/2023 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: icscert | Vendor: Nokia | Product: ASIK AirScale
Status : PUBLISHED

CVE-2022-2483 Description

The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.

Metrics

CVSS Version: 3.1 | Base Score: 8.4 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* CHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-1282
CWE Name: CWE-1282 Assumed-Immutable Data is Stored in Writable Memory
Source: Nokia

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).