CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “amperecomputing”

9 vulnerabilities found for “amperecomputing”

CVE-2025-62863
CRITICAL9.8

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PCIe driver’s S-EL0 address space.

amperecomputing / ampereone_a192-32m_firmware+13
Network
Published Dec 16, 2025
CVE-2025-62864
CRITICAL9.8

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write within the UEFI-MM Secure Partition context.

amperecomputing / ampereone_a192-32m_firmware+13
Network
Published Dec 16, 2025
CVE-2025-62862
MEDIUM4.6

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM Boot Error Record Table driver that could result in (1) an out-of-bounds read which leaks Secure-EL0 information to a process running in Non-Secure state or (2) an out-of-bounds write which corrupts Secure or Non-Secure memory, limited to memory mapped to UEFI-MM Secure Partition by the Secure Partition Manager.

amperecomputing / ampereone_a192-32m_firmware+13
Local
Published Dec 16, 2025
CVE-2022-46892
CRITICAL9.8

In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.

amperecomputing / ampere_altra_firmware+1
Network
Published Feb 15, 2023
CVE-2022-35888
MEDIUM6.5

Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel attack that extracts secret information from the CPU by correlating the power consumption with data being processed on the system.

amperecomputing / ampere_altra_max_firmware+2
Network
Published Sep 29, 2022
CVE-2022-37459
HIGH7.8

Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.

amperecomputing / ampere_altra_firmware+1
Local
Published Aug 17, 2022
CVE-2021-45454
HIGH7.5

Ampere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry via HWmon.

amperecomputing / ampere_altra_firmware+1
Network
Published Aug 17, 2022
CVE-2022-32295
CRITICAL9.8

On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access to SPI-NOR by the OS/hypervisor component.

amperecomputing / ampere_altra_firmware+1
Network
Published Jul 1, 2022
CVE-2022-25368
MEDIUM4.7

Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.

amperecomputing / ampere_altra_max_firmware+21
Local
Published Mar 10, 2022