CVE-2023-24478: Medium severity intel quartus prime software vulnerability
Published Aug 15, 2023
·Updated
Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable information disclosure via local access.
Affected Software
1 affected component
Intel Quartus Prime Software<22.4
Remediation
Event History
Aug 15, 2023
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Intel Agilex software vulnerability?
The vulnerability ID is CVE-2023-24478.
2
What is the severity rating of CVE-2023-24478?
The severity rating of CVE-2023-24478 is medium.
3
How can an authenticated user potentially enable information disclosure for this vulnerability?
An authenticated user can potentially enable information disclosure via local access.
4
Which Intel software is affected by CVE-2023-24478?
Intel Quartus Prime Pro Edition for Linux before version 22.4 is affected.
5
Is there a fix available for CVE-2023-24478?
Yes, upgrading to Intel Quartus Prime Pro Edition version 22.4 or later can fix the vulnerability.