CISA warns Nokia of critical vulnerability in industrial control system software

04. 11. 2022 Friday / By: Robert Denes / The key / Exact time: BST / Print this page

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert for three industrial control systems (ICS) about multiple vulnerabilities in software from ETIC Telecom, Nokia and Delta Industrial Automation.

CISA's flaw detection advisory covers three flaws in the Nokia ASIK AirScale 5G Common System Module (CVE-2022-2482, CVE-2022-2483, and CVE-2022-2484) that could allow arbitrary code execution and safe shutdown. boot function. All defects are rated 8.4 on the CVSS Severity Scale.

"Successful exploitation of the vulnerabilities could result in the execution of a malicious kernel, arbitrary malware, or modified Nokia programs," CISA noted.

The Finnish telecom giant has reportedly published instructions to mitigate the bugs affecting the ASIK 474021A.101 and ASIK 474021A.102 versions. The agency recommends that users contact Nokia directly for more information.


Via Link
gifgifgif

Phone

+44

Address

Canning Town, Barking Road
London E13 8EQ
United Kingdom