CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
10.8%
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.
Vendor | Product | Version | CPE |
---|---|---|---|
nokia | asik_airscale_474021a.102_firmware | - | cpe:2.3:o:nokia:asik_airscale_474021a.102_firmware:-:*:*:*:*:*:*:* |
nokia | asik_airscale_474021a.102 | - | cpe:2.3:h:nokia:asik_airscale_474021a.102:-:*:*:*:*:*:*:* |
nokia | asik_airscale_474021a.101_firmware | - | cpe:2.3:o:nokia:asik_airscale_474021a.101_firmware:-:*:*:*:*:*:*:* |
nokia | asik_airscale_474021a.101 | - | cpe:2.3:h:nokia:asik_airscale_474021a.101:-:*:*:*:*:*:*:* |
[
{
"defaultStatus": "unaffected",
"product": "ASIK AirScale ",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "474021A.101"
},
{
"status": "affected",
"version": "474021A.102"
}
]
}
]