Critical severity9.8NVD Advisory· Published Jul 1, 2022· Updated Jun 17, 2026
CVE-2022-32295
CVE-2022-32295
Description
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:amperecomputing:ampere_altra_firmware:*:*:*:*:*:*:*:*Range: <1.09
- cpe:2.3:o:amperecomputing:ampere_altra_max_firmware:*:*:*:*:*:*:*:*Range: <1.09
Patches
Vulnerability mechanics
References
3- amperecomputing.comnvdVendor Advisory
- amperecomputing.com/products/security-bulletins/altra-spi-nor-smc.htmlnvdVendor Advisory
- amperecomputing.com/products/security-bulletins/altra-spi-nor-smc-protection-for-ampere-website.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.