Description

A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.

Published: 2023-01-06
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Nokia has released technical support notes containing mitigation instructions for impacted Nokia users. Users should contact Nokia https://customer.nokia.com/support/s/  to receive further information.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-34741 A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.
History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Nokia Asik Airscale 474021a.101 Asik Airscale 474021a.101 Firmware Asik Airscale 474021a.102 Asik Airscale 474021a.102 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T22:03:09.854Z

Reserved: 2022-07-19T21:40:09.334Z

Link: CVE-2022-2482

cve-icon Vulnrichment

Updated: 2024-08-03T00:39:07.824Z

cve-icon NVD

Status : Modified

Published: 2023-01-06T22:15:09.077

Modified: 2024-11-21T07:01:05.100

Link: CVE-2022-2482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses