Vulnerability Description
Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.2 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Quartus Prime Pro | < 20.2 |
| Intel | Stratix 10 Fpga Firmware | - |
| Intel | Stratix 10 Fpga | - |
References
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00388Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00388Vendor Advisory
FAQ
What is CVE-2020-12312?
CVE-2020-12312 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.2 may allow an unauthenticated user to potentially e...
How severe is CVE-2020-12312?
CVE-2020-12312 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12312?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Quartus Prime Pro, Intel Stratix 10 Fpga Firmware, Intel Stratix 10 Fpga.