8.8
CVE-2022-2482
- EPSS 0.02%
- Veröffentlicht 06.01.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:05
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nokia ≫ Asik Airscale 474021a.102 Firmware Version-
Nokia ≫ Asik Airscale 474021a.101 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.047 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| ics-cert@hq.dhs.gov | 8.4 | 2 | 5.8 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
|
CWE-1274 Improper Access Control for Volatile Memory Containing Boot Code
The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.