Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAmperecomputing Ampere Altra
HWAmperecomputingwszystkie wersjeAmperecomputing Ampere Altra Firmware
OSAmperecomputing< 1.08gAmperecomputing Ampere Altra Max
HWAmperecomputingwszystkie wersjeAmperecomputing Ampere Altra Max Firmware
OSAmperecomputing< 2.05a
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Powiązane podatności
CVE-2022-46892CRITICAL9.8PL ✓ten sam produkt
Nieprawidłowa kontrola dostępu w Ampere Altra/AltraMax — reinicjalizacja root complex
CVE-2022-32295CRITICAL9.8PL ✓ten sam produkt
Niezabezpieczony dostęp do SPI-NOR w firmware Ampere Altra i Altra Max
CVE-2021-45454HIGH7.5ten sam produkt
Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry v...
CVE-2022-35888MEDIUM6.5ten sam produkt
Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power si...
CVE-2022-25368MEDIUM4.7ten sam produkt
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the C...