Buffer overflow in Intel Quartus Prime Pro - CVE-2020-8737

 

Buffer overflow in Intel Quartus Prime Pro - CVE-2020-8737

Published: November 12, 2020 / Updated: November 16, 2020


Vulnerability identifier: #VU48440
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8737
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to a boundary error in the Intel Stratix 10 FPGA firmware. An attacker with physical access can trigger memory corruption and enable escalation of privilege or information disclosure.


Affected software

Intel Quartus Prime Pro

How to mitigate CVE-2020-8737

Install updates from vendor's website.

Intel Quartus Prime Pro - update to 20.2

External References

Related Security Bulletins