CVE-2022-35888
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/09/2022
Last modified:
20/05/2025
Description
Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:amperecomputing:ampere_altra_max_firmware:*:*:*:*:*:*:*:* | 2022-07-15 (including) | |
| cpe:2.3:h:amperecomputing:ampere_altra_max:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amperecomputing:ampere_altra_firmware:*:*:*:*:*:*:*:* | 2022-07-15 (including) | |
| cpe:2.3:h:amperecomputing:ampere_altra:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amperecomputing:ampereone_firmware:*:*:*:*:*:*:*:* | 2022-07-15 (including) | |
| cpe:2.3:h:amperecomputing:ampereone:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



