CVE-2020-8737
Summary
| CVE | CVE-2020-8737 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-12 18:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.1 may allow an unauthenticated user to potentially enable escalation of privilege and/or information disclosure via physical access. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Intel | Quartus Prime | All | All | All | All |
| Application | Intel | Quartus Prime | All | All | All | All |
| Hardware | Intel | Stratix 10 Fpga | - | All | All | All |
| Hardware | Intel | Stratix 10 Fpga | - | All | All | All |
| Operating System | Intel | Stratix 10 Fpga Firmware | - | All | All | All |
| Operating System | Intel | Stratix 10 Fpga Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| INTEL-SA-00388 | MISC | www.intel.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.