Buffer overflow in Intel Quartus Prime Pro - CVE-2020-12312
Published: November 12, 2020 / Updated: November 16, 2020
Vulnerability identifier: #VU48443
CSH Severity: Low
CVSS v4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12312
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to a boundary error in the Intel Stratix 10 FPGA firmware. An attacker with physical access can trigger memory corruption and enable escalation of privilege.
Affected software
Intel Quartus Prime Pro
How to mitigate CVE-2020-12312
Install updates from vendor's website.
Intel Quartus Prime Pro - update to 20.2