Intel Quartus Prime vulnerabilities
43 known vulnerabilities affecting intel/quartus_prime.
Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH28MEDIUM15
Vulnerabilities
Page 1 of 3
CVE-2020-24454P3HIGHCVSS 7.5≤ 20.1fixed in 20.32020-11-12
CVE-2020-24454 [HIGH] CWE-611 CVE-2020-24454: Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro
Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via network access.
nvd
CVE-2022-27233P3HIGHCVSS 7.5≤ 21.1fixed in 22.12022-11-11
CVE-2022-27233 [HIGH] CWE-91 CVE-2022-27233: XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Stan
XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.
nvd
CVE-2022-21205P3HIGHCVSS 7.5fixed in 21.32022-02-09
CVE-2022-21205 [HIGH] CWE-611 CVE-2022-21205: Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Pri
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.
nvd
CVE-2018-3683P3HIGHCVSS 7.8≥ 15.1, ≤ 18.02018-07-10
CVE-2018-3683 [HIGH] CWE-428 CVE-2018-3683: Unquoted service paths in Intel Quartus Prime in versions 15.1 - 18.0 allow a local attacker to pote
Unquoted service paths in Intel Quartus Prime in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.
nvd
CVE-2021-44454P3HIGHCVSS 7.8fixed in 21.32022-02-09
CVE-2021-44454 [HIGH] CWE-20 CVE-2021-44454: Improper input validation in a third-party component for Intel(R) Quartus(R) Prime Pro Edition befor
Improper input validation in a third-party component for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-21220P3HIGHCVSS 7.8fixed in 21.32022-02-09
CVE-2022-21220 [HIGH] CWE-611 CVE-2022-21220: Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version
Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-32570P3HIGHCVSS 7.8fixed in 22.1fixed in 22.22023-02-16
CVE-2022-32570 [HIGH] CWE-287 CVE-2022-32570: Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an
Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2024-38383P3HIGHCVSS 7.8fixed in 24.22024-11-13
CVE-2024-38383 [HIGH] CWE-427 CVE-2024-38383: Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before
Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2024-38668P3HIGHCVSS 7.8fixed in 23.1.12024-11-13
CVE-2024-38668 [HIGH] CWE-427 CVE-2024-38668: Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows be
Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2024-22184P3HIGHCVSS 7.8fixed in 24.12024-08-14
CVE-2024-22184 [HIGH] CWE-427 CVE-2024-22184: Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before versi
Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2024-23907P3HIGHCVSS 7.8fixed in 23.42024-08-14
CVE-2024-23907 [HIGH] CWE-427 CVE-2024-23907: Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4
Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-21174P3HIGHCVSS 7.8fixed in 21.32022-02-09
CVE-2022-21174 [HIGH] CVE-2022-21174: Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before v
Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-33892P3HIGHCVSS 7.8fixed in 22.1fixed in 22.22023-02-16
CVE-2022-33892 [HIGH] CWE-22 CVE-2022-33892: Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenti
Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-26840P3HIGHCVSS 7.8fixed in 22.1fixed in 22.22023-02-16
CVE-2022-26840 [HIGH] CVE-2022-26840: Improper neutralization in the Intel(R) Quartus Prime Pro and Standard edition software may allow an
Improper neutralization in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-41693P3HIGHCVSS 7.8fixed in 22.32023-05-10
CVE-2022-41693 [HIGH] CWE-427 CVE-2022-41693: Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 m
Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-34157P3HIGHCVSS 7.8fixed in 21.1fixed in 21.32023-02-16
CVE-2022-34157 [HIGH] CVE-2022-34157: Improper access control in the Intel(R) FPGA SDK for OpenCL(TM) with Intel(R) Quartus(R) Prime Pro E
Improper access control in the Intel(R) FPGA SDK for OpenCL(TM) with Intel(R) Quartus(R) Prime Pro Edition software before version 22.1 may allow authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-27187P3HIGHCVSS 7.8≤ 21.12022-11-11
CVE-2022-27187 [HIGH] CWE-427 CVE-2022-27187: Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before vers
Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-14603P4HIGHCVSS 7.8fixed in 19.32019-12-16
CVE-2019-14603 [HIGH] CWE-276 CVE-2019-14603: Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-21204P4HIGHCVSS 7.8fixed in 21.32022-02-09
CVE-2022-21204 [HIGH] CWE-276 CVE-2022-21204: Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an auth
Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-21203P4HIGHCVSS 7.8fixed in 21.12022-02-09
CVE-2022-21203 [HIGH] CWE-281 CVE-2022-21203: Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition b
Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
1 / 3Next →