CVE-2022-32295

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/07/2022
Last modified:
08/08/2023

Description

On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amperecomputing:ampere_altra_firmware:*:*:*:*:*:*:*:* 1.09 (excluding)
cpe:2.3:h:amperecomputing:ampere_altra:-:*:*:*:*:*:*:*
cpe:2.3:o:amperecomputing:ampere_altra_max_firmware:*:*:*:*:*:*:*:* 1.09 (excluding)
cpe:2.3:h:amperecomputing:ampere_altra_max:-:*:*:*:*:*:*:*