Lucene search

K
cveIntelCVE-2022-37329
HistoryFeb 16, 2023 - 8:15 p.m.

CVE-2022-37329

2023-02-1620:15:15
CWE-427
intel
web.nvd.nist.gov
25
cve-2022-37329
intel quartus
software
uncontrolled search path
privilege escalation

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

13.2%

Uncontrolled search path in some Intel® Quartus® Prime Pro and Standard Edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected configurations

Nvd
Node
intelfpga_software_development_kitRange<22.1proopencl
OR
intelquartus_primeRange<21.1standard
OR
intelquartus_primeRange<21.3pro
VendorProductVersionCPE
intelfpga_software_development_kit*cpe:2.3:a:intel:fpga_software_development_kit:*:*:*:*:pro:opencl:*:*
intelquartus_prime*cpe:2.3:a:intel:quartus_prime:*:*:*:*:standard:*:*:*
intelquartus_prime*cpe:2.3:a:intel:quartus_prime:*:*:*:*:pro:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Intel(R) Quartus(R) Prime Pro and Standard Edition software",
    "versions": [
      {
        "version": "See references",
        "status": "affected"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

EPSS

0

Percentile

13.2%

Related for CVE-2022-37329