CVE-2022-2482

A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02 Third Party Advisory US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nokia:asik_airscale_474021a.102_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nokia:asik_airscale_474021a.102:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nokia:asik_airscale_474021a.101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nokia:asik_airscale_474021a.101:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:01

Type Values Removed Values Added
References () https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02 - Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02 - Third Party Advisory, US Government Resource
Summary
  • (es) Existe una vulnerabilidad en el módulo del sistema ASIK AirScale de Nokia (versiones 474021A.101 y 474021A.102) que podría permitir a un atacante colocar un script en el sistema de archivos accesible desde Linux. Un script colocado en el lugar apropiado podría permitir la ejecución de código arbitrario en el gestor de arranque.
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 8.4

Information

Published : 2023-01-06 22:15

Updated : 2024-11-21 07:01


NVD link : CVE-2022-2482

Mitre link : CVE-2022-2482

CVE.ORG link : CVE-2022-2482


JSON object : View

Products Affected

nokia

  • asik_airscale_474021a.102_firmware
  • asik_airscale_474021a.101_firmware
  • asik_airscale_474021a.102
  • asik_airscale_474021a.101
CWE
CWE-1274

Improper Access Control for Volatile Memory Containing Boot Code