CVE-2022-37459
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/08/2022
Last modified:
18/08/2022
Description
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:amperecomputing:ampere_altra_firmware:*:*:*:*:*:*:*:* | 1.08g (excluding) | |
| cpe:2.3:h:amperecomputing:ampere_altra:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amperecomputing:ampere_altra_max_firmware:*:*:*:*:*:*:*:* | 2.05a (excluding) | |
| cpe:2.3:h:amperecomputing:ampere_altra_max:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



