Out-of-bounds write in Intel products - CVE-2023-49614
Published: May 22, 2024
Vulnerability identifier: #VU89739
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49614
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A local administrator can trigger an out-of-bounds write and gain access to sensitive information or escalate privileges on the system.
Affected software
Intel Agilex 7 FPGA and SoC FPGA
Intel Stratix 10 FPGA and SoC FPGA
Intel Field Programmable Gate Array (FPGA)
Intel Stratix 10 FPGA and SoC FPGA
Intel Field Programmable Gate Array (FPGA)
How to mitigate CVE-2023-49614
Install updates from vendor's website.
Intel Field Programmable Gate Array (FPGA) - update to 2.9.0