VYPR

Ampere Altra Max Firmware

by Amperecomputing

CVEs (2)

  • CVE-2022-32295CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.01

    On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.

  • CVE-2022-35888MedSep 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.