CVE-2022-35888: Medium severity ampere computing ampere altra max firmware vulnerability
Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35888?
CVE-2022-35888 is a vulnerability that affects Ampere Altra and Ampere Altra Max devices and allows attacks via Hertzbleed, a power side-channel attack that extracts secret information from the CPU.
What is Hertzbleed?
Hertzbleed is a power side-channel attack that extracts secret information from the CPU.
Which devices are affected by CVE-2022-35888?
Ampere Altra and Ampere Altra Max devices are affected by CVE-2022-35888.
What is the severity of CVE-2022-35888?
CVE-2022-35888 has a severity rating of 6.5 (Medium).
How can I fix CVE-2022-35888?
To fix CVE-2022-35888, users should apply the latest firmware updates provided by Amperecomputing.