Vulnerability Description
Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amperecomputing | Ampere Altra Firmware | < 1.08b |
| Amperecomputing | Ampere Altra | - |
| Amperecomputing | Ampere Altra Max Firmware | < 2.05 |
| Amperecomputing | Ampere Altra Max | - |
References
- https://amperecomputing.com/product-security/Broken LinkVendor Advisory
- https://amperecomputing.com/products/security-bulletins/platypus.htmlPatchVendor Advisory
- https://amperecomputing.com/product-security/Broken LinkVendor Advisory
- https://amperecomputing.com/products/security-bulletins/platypus.htmlPatchVendor Advisory
FAQ
What is CVE-2021-45454?
CVE-2021-45454 is a vulnerability with a CVSS score of 7.5 (HIGH). Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon.
How severe is CVE-2021-45454?
CVE-2021-45454 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45454?
Check the references section above for vendor advisories and patch information. Affected products include: Amperecomputing Ampere Altra Firmware, Amperecomputing Ampere Altra, Amperecomputing Ampere Altra Max Firmware, Amperecomputing Ampere Altra Max.