ZeroHour

CVE-2022-37459

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
Description

Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.

Vendors
amperecomputing
Products
ampere altra firmware, ampere altra max firmware
Weakness
CWE-203
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.