Database/Firmware, BMC & network fabric

Ampere Altra / Altra Max processors: The Arm-server variant of Hertzbleed
CVSS 6.3CVE-2022-35888Firmware, BMC & network fabricHertzbleed (Ampere Altra)curated
Impact
The Arm-server variant of Hertzbleed. Relevant because Ampere Altra is a common host CPU under GPU nodes in Arm-based AI racks and in several neocloud fleets - operators who assumed the Hertzbleed story was x86-only still have it.
Who can reach it
Authenticated user able to time operations, including over the network against host crypto.
What to do
Ampere published a security bulletin rather than a firmware fix. Mitigation is constant-time crypto and, at high cost, disabling frequency scaling. Treat as UNPATCHABLE in hardware.
References
Related entries
- AMI MegaRAC SPx (BMC cryptography / HMAC): A step is missing when the BMC generates its HMAC, so the authentication tagCVE-2023-34471 · AMI MegaRAC SPx (BMC cryptography / HMAC)Medium
- AMD Video Decoder Engine Firmware (VCN FW) - debug code left active: Debug code was shipped active in AMD's Video CoreCVE-2024-36319 · AMD Video Decoder Engine Firmware (VCN FW) - debug code left activeMedium
- EDK II NetworkPkg (IScsiDxe, iSCSI login response processing): A hostile iSCSI target answers the firmware initiatorCVE-2024-38805 · EDK II NetworkPkg (IScsiDxe, iSCSI login response processing)Medium
- Lenovo XClarity Administrator (LXCA, insufficient authorization): An authenticated LXCA user without sufficientCVE-2024-45104 · Lenovo XClarity Administrator (LXCA, insufficient authorization)Medium
- Keylime verifier: hardcoded TPM quote nonce lets a compromised node replay stockpiled attestationsCVE-2026-6420 · Keylime verifier (TPM quote nonce, push attestation model)Medium
- Arista EOS: ingress ACLs on shared SVIs stop enforcing after a secondary switch card eventCVE-2026-73451 · Arista EOS ingress security ACLs on shared-mode SVIs (dual switch card systems)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.