CVE-2022-2484: High severity nokia asika airscale vulnerability
Published Jan 6, 2023
·Updated
The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.
Affected Software
4 affected components
Nokia ASIK 474021A.101
Nokia ASIK 474021A.102 (not affected by CVE-2022-2484)
Nokia Asik Airscale 474021a.101 Firmware
Nokia Asik Airscale 474021a.101
Remediation
Information
Nokia has released technical support notes containing mitigation instructions for impacted Nokia users. Users should contact Nokia https://customer.nokia.com/support/s/ to receive further information.
Event History
Jan 6, 2023
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
RemedyDescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via ICS·12:47 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2484.
2
What is the severity rating of CVE-2022-2484?
The severity rating of CVE-2022-2484 is 7.8 (high).
3
What is the affected software for CVE-2022-2484?
The affected software for CVE-2022-2484 is Nokia Asik Airscale 474021a.101 Firmware.
4
How can an attacker exploit CVE-2022-2484?
An attacker can exploit CVE-2022-2484 by bypassing the signature check in the Nokia ASIK AirScale system module version 474021A.101 and running modified firmware.
5
Is there a fix available for CVE-2022-2484?
Please refer to the official reference link for information on any available fixes for CVE-2022-2484.