CVE-2022-2483
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
- EPSS probability
- 0.06%
- CWE
- CWE-1282
- Published
- 2023-01-06
- Last modified
- 2026-03-13
Affected products
- Nokia ASIK AirScale
- Nokia ASIK AirScale
Weakness type
Related vulnerabilities
- CVE-2018-25229 — BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
- CVE-2019-25590 — Axessh 4.2 Denial of Service via Log File Name
- CVE-2019-25588 — BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
- CVE-2019-25587 — BulletProof FTP Server 2019.0.0.50 Storage-Path Denial of Service
- CVE-2019-25583 — RarmaRadio 2.72.3 Username Field Denial of Service
- CVE-2019-25551 — Sandboxie 5.30 Denial of Service via Program Alerts Buffer Overflow
- CVE-2019-25358 — FileOptimizer 14.00.2524 - Denial of Service