Altra
by Ampere
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46892 | 0.00 | — | 0.01 | Feb 15, 2023 | In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex. | |||
| CVE-2022-35888 | 0.00 | — | 0.01 | Sep 29, 2022 | Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system. | |||
| CVE-2022-37459 | 0.00 | — | 0.00 | Aug 17, 2022 | Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue. | |||
| CVE-2021-45454 | 0.00 | — | 0.01 | Aug 17, 2022 | Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon. | |||
| CVE-2022-32295 | 0.00 | — | 0.01 | Jun 30, 2022 | On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component. |
- CVE-2022-46892Feb 15, 2023risk 0.00cvss —epss 0.01
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
- CVE-2022-35888Sep 29, 2022risk 0.00cvss —epss 0.01
Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.
- CVE-2022-37459Aug 17, 2022risk 0.00cvss —epss 0.00
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
- CVE-2021-45454Aug 17, 2022risk 0.00cvss —epss 0.01
Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon.
- CVE-2022-32295Jun 30, 2022risk 0.00cvss —epss 0.01
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.