First published: Thu Nov 12 2020(Updated: )
Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Quartus Prime | <=20.1 | |
Intel Quartus Prime | <20.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2020-24454.
The severity of CVE-2020-24454 is high with a CVSS score of 7.5.
The affected software is Intel Quartus Prime Pro Edition before version 20.3 and Intel Quartus Prime Standard Edition before version 20.2.
CVE-2020-24454 may allow an unauthenticated user to potentially enable information disclosure via network access.
To fix CVE-2020-24454, update to Intel Quartus Prime Pro Edition version 20.3 or Intel Quartus Prime Standard Edition version 20.2.