« Back to list

Amperecomputing

Amperecomputing Ampere Altra MAX Firmware: vulnerabilities and CVEs

Amperecomputing Ampere Altra MAX Firmware has 6 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months0
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-46892Critical (9.8)0.62%—Feb 15, 2023
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
CVE-2022-35888Medium (6.5)0.70%—Sep 29, 2022
Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with…
CVE-2022-37459High (7.8)0.22%—Aug 17, 2022
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel…
CVE-2021-45454High (7.5)0.72%—Aug 17, 2022
Ampere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry via HWmon.
CVE-2022-32295Critical (9.8)1.3%—Jul 1, 2022
On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.
CVE-2022-25368Medium (4.7)0.30%—Mar 10, 2022
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these…

Other products by Amperecomputing