8.8
CVE-2022-2482
- EPSS 0.03%
- Veröffentlicht 06.01.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:05
- Quelle ics-cert@hq.dhs.gov
- Teams Watchlist Login
- Unerledigt Login
A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nokia ≫ Asik Airscale 474021a.102 Firmware Version-
Nokia ≫ Asik Airscale 474021a.101 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.082 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
ics-cert@hq.dhs.gov | 8.4 | 2 | 5.8 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
|
CWE-1274 Improper Access Control for Volatile Memory Containing Boot Code
The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.