CVE-2022-38788: Medium severity nokia fastmile firmware vulnerability
An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-38788.
What is the severity rating of CVE-2022-38788?
The severity rating of CVE-2022-38788 is medium with a score of 4.3.
What is the affected software and version?
The affected software and version is Nokia FastMile 5G Receiver Firmware 1.2104.00.0281.
How does the vulnerability in Nokia FastMile 5G Receiver work?
The vulnerability allows an attacker to passively intercept a pairing handshake and retrieve the PIN and LTK (long-term key) through outdated Bluetooth pairing mechanisms.
Is there a fix available for this vulnerability?
Please refer to the official Nokia website (https://www.nokia.com/notices/responsible-disclosure/) for information on any available fixes or patches.