CVE-2022-21220: XEE
Published Feb 9, 2022
·Updated
Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
1 affected component
Intel Quartus Prime Software<21.3
Event History
Feb 9, 2022
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Intel Quartus Prime Pro Edition vulnerability?
The vulnerability ID for this Intel Quartus Prime Pro Edition vulnerability is CVE-2022-21220.
2
What is the severity level of CVE-2022-21220?
The severity level of CVE-2022-21220 is high (7.8).
3
How does CVE-2022-21220 impact Intel Quartus Prime Pro Edition?
CVE-2022-21220 may allow an authenticated user with local access to potentially enable escalation of privilege.
4
Which version of Intel Quartus Prime Pro Edition is affected by CVE-2022-21220?
Intel Quartus Prime Pro Edition before version 21.3 is affected by CVE-2022-21220.
5
How can I fix the CVE-2022-21220 vulnerability in Intel Quartus Prime Pro Edition?
To fix the CVE-2022-21220 vulnerability in Intel Quartus Prime Pro Edition, update to version 21.3 or later.