Vulnerability record · CVE-2022-25368 · published 10 March 2022
CVE-2022-25368: Amperecomputing ampere altra max firmware vulnerability
Amperecomputing · Ampere Altra Max Firmware
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.
Description
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://amperecomputing.com/products/security-bulletins/impact-of-spectre-bhb-on-ampere.html | Vendor Advisory |
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23960 | Third Party AdvisoryVDB Entry |
| https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/spectre-bhb | PatchTechnical DescriptionVendor Advisory |
| https://amperecomputing.com/products/security-bulletins/impact-of-spectre-bhb-on-ampere.html | Vendor Advisory |
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23960 | Third Party AdvisoryVDB Entry |
| https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability/spectre-bhb | PatchTechnical DescriptionVendor Advisory |
Track CVE-2022-25368 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25368), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.