CVE-2022-2484 Vulnerability Details

  /     /     /  

CVE-2022-2484 Metadata Quick Info

CVE Published: 06/01/2023 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: icscert | Vendor: Nokia | Product: ASIK AirScale
Status : PUBLISHED

CVE-2022-2484 Description

The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.

Metrics

CVSS Version: 3.1 | Base Score: 8.4 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* CHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-1274
CWE Name: CWE-1274 Improper Access Control for Volatile Memory Containing Boot Code
Source: Nokia

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).