nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-2483 CVE-2022-2483
HIGH
Record summary
CVE-2022-2483 has a selected CVSS score of 8.4 (high).
Description
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ASIK AirScaleBrowse Nokia / ASIK AirScaleDefault status: unaffected | CVE List | 474021A.101 | affected |
| 474021A.102 | affected |
References
2cisa.govGovernment resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-02