CVE-2020-8737 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Intel Quartus Prime
Severity
6.8MEDIUMNVD
EPSS
0.1%
top 77.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateMay 24
Description
Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.1 may allow an unauthenticated user to potentially enable escalation of privilege and/or information disclosure via physical access.
CVSS vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 0.9 | Impact: 5.9
Affected Packages1 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-wxq2-wrr8-f54g: Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20↗2022-05-24
CVEList▶
CVE-2020-8737: Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20↗2020-11-12