Vulnerability Details CVE-2022-37459
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.9%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2022-37459
-
cpe:2.3:h:amperecomputing:ampere_altra:-
-
cpe:2.3:h:amperecomputing:ampere_altra_max:-
-
cpe:2.3:o:amperecomputing:ampere_altra_firmware:-
-
cpe:2.3:o:amperecomputing:ampere_altra_firmware:1.08b
-
cpe:2.3:o:amperecomputing:ampere_altra_max_firmware:-
-
cpe:2.3:o:amperecomputing:ampere_altra_max_firmware:1.09
-
cpe:2.3:o:amperecomputing:ampere_altra_max_firmware:2.05