CVE-2022-46892: Critical severity ampere computing ampere altra firmware vulnerability
Published Feb 15, 2023
·Updated
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
Affected Software
8 affected components
Amperecomputing Ampere Altra Firmware<2.10c
Amperecomputing Ampere Altra
Amperecomputing Ampere Altra Max Firmware<2.10c
Amperecomputing Ampere Altra Max
All of the following
Amperecomputing Ampere Altra Firmware<2.10c
Amperecomputing Ampere Altra
All of the following
Amperecomputing Ampere Altra Max Firmware<2.10c
Amperecomputing Ampere Altra Max
Event History
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-46892.
2
What is the severity of CVE-2022-46892?
The severity of CVE-2022-46892 is critical (9.8).
3
Which software versions are affected by CVE-2022-46892?
Ampere Altra and Ampere AltraMax firmware versions up to exclusive 2.10c are affected.
4
What is the impact of CVE-2022-46892?
CVE-2022-46892 allows the OS to reinitialize a disabled root complex.
5
How can I fix CVE-2022-46892?
To fix CVE-2022-46892, update the Ampere Altra and Ampere AltraMax firmware to version 2.10c or higher.