PT-2022-24567 · Nokia · Nokia Fastmile 5G Receiver 5G14-B+1
Daniel Wong
·
Published
2022-09-15
·
Updated
2022-09-20
·
CVE-2022-38788
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nokia FastMile 5G Receiver 5G14-B version 1.2104.00.0281
Description
An issue was discovered in the Bluetooth pairing mechanism of the Nokia ODU, which uses outdated pairing mechanisms. This allows an attacker to passively intercept a pairing handshake and, after offline cracking, retrieve the PIN and long-term key (LTK).
Recommendations
For Nokia FastMile 5G Receiver 5G14-B version 1.2104.00.0281, consider disabling Bluetooth until a patch or update is available to address the outdated pairing mechanisms. Restrict access to the Bluetooth functionality to minimize the risk of exploitation. Avoid using the device's Bluetooth feature for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nokia Fastmile 5G Receiver 5G14-B
Nokia Odu