First published: Fri Jan 06 2023(Updated: )
The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia Asik Airscale 474021a.101 Firmware | ||
Nokia Asik Airscale 474021a.101 | ||
Nokia ASIK 474021A.101 | ||
Nokia ASIK 474021A.102 (not affected by CVE-2022-2484) |
Nokia has released technical support notes containing mitigation instructions for impacted Nokia users. Users should contact Nokia https://customer.nokia.com/support/s/ to receive further information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-2484.
The severity rating of CVE-2022-2484 is 7.8 (high).
The affected software for CVE-2022-2484 is Nokia Asik Airscale 474021a.101 Firmware.
An attacker can exploit CVE-2022-2484 by bypassing the signature check in the Nokia ASIK AirScale system module version 474021A.101 and running modified firmware.
Please refer to the official reference link for information on any available fixes for CVE-2022-2484.