ZeroHour

CVE-2022-35888

CVSS 3.1
6.5 medium
EPSS
<1%p49
Published
()
Modified
Description

Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.

Vendors
amperecomputing
Products
ampere altra max firmware, ampere altra firmware, ampereone firmware
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.