PT-2023-12766 · Nokia · Asik Airscale

Joel Cretan

·

Publicado

2023-01-06

·

Atualizado

2023-01-12

·

CVE-2022-2482

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nokia ASIK AirScale system module versions 474021A.101 through 474021A.102
Description A vulnerability exists in Nokia’s ASIK AirScale system module that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.
Recommendations For versions 474021A.101 and 474021A.102, consider restricting access to the file system to prevent an attacker from placing a malicious script, until a patch is available. As a temporary workaround, consider disabling any functionality that allows scripts to be executed from the Linux-accessible file system.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-2482

Produtos afetados

Asik Airscale