HIGH🇬🇧 English

CVE-2022-37459

CVSS 7.8v3.1pub. 2022-08-17upd. 2024-11-21

Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Amperecomputing Ampere Altra

    HW
    Amperecomputing
    wszystkie wersje
  • Amperecomputing Ampere Altra Firmware

    OS
    Amperecomputing
    < 1.08g
  • Amperecomputing Ampere Altra Max

    HW
    Amperecomputing
    wszystkie wersje
  • Amperecomputing Ampere Altra Max Firmware

    OS
    Amperecomputing
    < 2.05a
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Referencje

Powiązane podatności

CVE-2022-46892CRITICAL9.8PL ✓ten sam produkt

Nieprawidłowa kontrola dostępu w Ampere Altra/AltraMax — reinicjalizacja root complex

CVE-2022-32295CRITICAL9.8PL ✓ten sam produkt

Niezabezpieczony dostęp do SPI-NOR w firmware Ampere Altra i Altra Max

CVE-2021-45454HIGH7.5ten sam produkt

Ampere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry v...

CVE-2022-35888MEDIUM6.5ten sam produkt

Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power si...

CVE-2022-25368MEDIUM4.7ten sam produkt

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the C...