Loading
Generated remediation guidance and an executive summary. No account required.
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.
Use CWE-203, Amperecomputing vendor hub and Ampere Altra Firmware product page to widen CVE-2022-37459 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-46892, CVE-2022-32295 and CVE-2021-45454 for nearby disclosures in the same product family.