Vulnerability Description
An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nokia | Fastmile 5G Receiver Firmware | 1.2104.00.0281 |
| Nokia | Fastmile 5G Receiver | - |
References
- https://github.com/ProxyStaffy/Nokia-FastMile-5G-Receiver-5G14-BExploitThird Party Advisory
- https://www.nokia.com/notices/responsible-disclosure/Vendor Advisory
- https://github.com/ProxyStaffy/Nokia-FastMile-5G-Receiver-5G14-BExploitThird Party Advisory
- https://www.nokia.com/notices/responsible-disclosure/Vendor Advisory
FAQ
What is CVE-2022-38788?
CVE-2022-38788 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake...
How severe is CVE-2022-38788?
CVE-2022-38788 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38788?
Check the references section above for vendor advisories and patch information. Affected products include: Nokia Fastmile 5G Receiver Firmware, Nokia Fastmile 5G Receiver.