Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w2m-f6qv-243x

Опубликовано: 07 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.

The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.

EPSS

Процентиль: 17%
0.00056
Низкий

7.1 High

CVSS3

Дефекты

CWE-1282

Связанные уязвимости

CVSS3: 8.4
nvd
около 3 лет назад

The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.

EPSS

Процентиль: 17%
0.00056
Низкий

7.1 High

CVSS3

Дефекты

CWE-1282