← Vulnerability feed

Vulnerability record · CVE-2022-25368 · published 10 March 2022

CVE-2022-25368: Amperecomputing ampere altra max firmware vulnerability

Amperecomputing · Ampere Altra Max Firmware

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

4.7 CVSS 3.1 Medium EPSS 0.30% · top 79.7%
4.7CVSS 3.1 base score, v2 1.9
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
22Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25368 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-46892Amperecomputing ampere altra firmware improper access control vulnerabilityIn Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.EPSS 0.62%9.8CVE-2022-32295Amperecomputing ampere altra firmware vulnerabilityOn Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervi…EPSS 1.3%7.8CVE-2022-37459Amperecomputing ampere altra firmware observable discrepancy vulnerabilityAmpere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and poten…EPSS 0.22%7.5CVE-2022-48251Arm cortex-a53 firmware observable discrepancy vulnerabilityThe AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor repor…EPSS 0.83%7.5CVE-2021-45454Amperecomputing ampere altra firmware vulnerabilityAmpere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry via HWmon.EPSS 0.72%6.5CVE-2022-35888Amperecomputing ampere altra max firmware observable discrepancy vulnerabilityAmpere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret …EPSS 0.70%5.6CVE-2022-23960Xen vulnerabilityCertain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage t…EPSS 0.50%5.5CVE-2020-13844Arm cortex-a32 firmware observable discrepancy vulnerabilityArm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of info…EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2022-25368), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.