Skip to main content
Home
Search Icon

Search

×
Info Icon

Some of our content has been moved to altera.com and we are working on migrating the remaining content and experiences. Let us help you find what you’re looking for.

Having a hard time finding something? Contact us

  • Products

    Products

    View All Products
    FPGAs, SoCs, CPLDs
    High-Performance
    Agilex 9 Agilex 7 Stratix 10
    Mid-Range
    Agilex 5 Arria 10 Arria V
    Power and Cost-Optimized
    Agilex 3 MAX 10 MAX V Cyclone 10 Cyclone V Cyclone IV
    Development Software & Tools
    AI Development Tools
    FPGA AI Suite
    FPGA Design & Simulation Tools
    Quartus Prime Design Software Power and Thermal Analyzer Questa* – Altera FPGA Edition Advanced Link Analyzer Open FPGA Stack (OFS) Transceiver Toolkit
    Embedded Design Tools & Software
    Ashling RISCFree IDE Visual Designer Studio Intel Simics Simulator for Altera FPGAs ARM SoC EDS
    IP Development Tools
    DSP Builder HLS IP Gen (Beta) Altera FPGA Add-on for oneAPI Base Toolkit P4 Suite for FPGAs
    Development Kits
    High-Performance
    Agilex 9 Agilex 7 Stratix 10
    Mid-Range
    Agilex 5 Arria 10 Arria V
    Power and Cost-Optimized
    Agilex 3 MAX 10 MAX V Cyclone 10 Cyclone V Cyclone IV
    Intellectual Property
    Interfaces
    PCI Express Compute Express Link (CXL) Ethernet Audio / Video Communication High Speed Serial Networking / Security
    Memory Controllers
    DMA Flash SDRAM SRAM
    Digital Signal Processing & AI
    AI Video & Image Processing Floating Point Error Correction Modulation Filters / Transforms
    Soft Embedded Processors
    Nios V
    Transceivers & Basic Functions
    Clocks, PLLs & Resets Transceivers Simulation, Debug & Verification
  • Solutions

    Solutions

    Industries
    Broadcast & Pro AV Consumer Electronics Data Center
    Industrial Medical Aerospace & Defense
    Test & Measurement Transportation Wireless Wireline
    Technology & Applications
    Technology
    Why FPGAs? Physical AI Quantum Computing Security
    Applications
    Robotics Solutions Stack Holoscan Sensor Bridge Video Solutions Stack
  • Design

    Design

    View All Design
    Download & License Center
    FPGA Development Tools
    Quartus Prime Pro Quartus Prime Standard Quartus Prime Lite Quartus II Subscription Edition Quartus II Web Edition
    Embedded Tools
    Arm* Development Studio for Altera® SoC FPGA Altera® SoC EDS Pro Altera® SoC EDS Standard
    Add-On Development Tools
    HLS IP Gen (Beta) DSP Builder Pro DSP Builder Standard SDK for OpenCL™ Pro SDK for OpenCL™ Standard SDK for OpenCL™ Subscription Edition SDK for OpenCL™ Web Edition FPGA AI Suite
    Simulation Tools
    Questa*-Altera® FPGA Edition Pro Questa*-Altera® FPGA Edition Standard ModelSim-Altera® FPGAs Pro ModelSim-Altera® FPGAs Standard Simics® Simulator for Altera® FPGA
    Utilities
    Flexlm License Daemons Software Advanced Link Analyzer Pro Advanced Link Analyzer Standard Jam STAPL Player Jam STAPL Byte-Code Player
    Licensing
    Self Service License Center Licensing Support Center
    Design Hubs & Training
    Design Hubs
    Agilex 7 Agilex 5 Agilex 3 View all Design Hubs
    Developer Centers
    Stratix 10 Arria 10 Cyclone 10 GX Cyclone 10 LP MAX 10 View all Developer Centers
    Training
    Training Overview My Learning eLearning Catalog Instructor-Led Training Catalog All Altera FPGA Training Learning Plans How to Begin a Simple FPGA Design How To Videos
    Example Designs
    FPGA Developer Site
    Example Designs Zephyr Drivers Linux Drivers See All
    Design Store
    Agilex 7 Agilex 5 MAX 10 See All
    Documentation
    All FPGA Documentation
    By Product Family IP Docs Dev Software Docs Release Notes Application Notes Device Overviews Datasheets Errata/Known Issues User Guides Pin Connection Guidelines Pinouts Package Drawings
    Design Resources
    Quartus Support Center Step-by-Step Dev Guidance Example Designs Docs & Resources by Family PCB Resources Package Drawings Pinouts Quality & Reliability Find Boards / Dev Kits Find IP Find Partners Find Knowledge Articles
    Partners
    Find Partners Find Offerings About ASAP Join Now Sign In
  • Support

    Support

    Support
    Community Forums Knowledge Articles University Program
    Premier Support Supplier Portal Quality & Reliability
  • About

    About

    About
    Company Overview Newsroom Events
    Careers Blogs
    Management Team Board of Directors
  • Contact Us

    Contact Us

    • FPGAs, SoCs, CPLDs
      • High-Performance
        • Agilex 9
        • Agilex 7
        • Stratix 10
      • Mid-Range
        • Agilex 5
        • Arria 10
        • Arria V
      • Power and Cost-Optimized
        • Agilex 3
        • MAX 10
        • MAX V
        • Cyclone 10
        • Cyclone V
        • Cyclone IV
    • Development Software & Tools
      • AI Development Tools
        • FPGA AI Suite
      • FPGA Design & Simulation Tools
        • Quartus Prime Design Software
        • Power and Thermal Analyzer
        • Questa* – Altera FPGA Edition
        • Advanced Link Analyzer
        • Open FPGA Stack (OFS)
        • Transceiver Toolkit
      • Embedded Design Tools & Software
        • Ashling RISCFree IDE
        • Visual Designer Studio
        • Intel Simics Simulator for Altera FPGAs
        • ARM SoC EDS
      • IP Development Tools
        • DSP Builder
        • HLS IP Gen (Beta)
        • Altera FPGA Add-on for oneAPI Base Toolkit
        • P4 Suite for FPGAs
    • Development Kits
      • High-Performance
        • Agilex 9
        • Agilex 7
        • Stratix 10
      • Mid-Range
        • Agilex 5
        • Arria 10
        • Arria V
      • Power and Cost-Optimized
        • Agilex 3
        • MAX 10
        • MAX V
        • Cyclone 10
        • Cyclone V
        • Cyclone IV
    • Intellectual Property
      • Interfaces
        • PCI Express
        • Compute Express Link (CXL)
        • Ethernet
        • Audio / Video
        • Communication
        • High Speed
        • Serial
        • Networking / Security
      • Memory Controllers
        • DMA
        • Flash
        • SDRAM
        • SRAM
      • Digital Signal Processing & AI
        • AI
        • Video & Image Processing
        • Floating Point
        • Error Correction
        • Modulation
        • Filters / Transforms
      • Soft Embedded Processors
        • Nios V
      • Transceivers & Basic Functions
        • Clocks, PLLs & Resets
        • Transceivers
        • Simulation, Debug & Verification
    View All Products
    • Industries
        • Broadcast & Pro AV
        • Consumer Electronics
        • Data Center
        • Industrial
        • Medical
        • Aerospace & Defense
        • Test & Measurement
        • Transportation
        • Wireless
        • Wireline
    • Technology & Applications
      • Technology
        • Why FPGAs?
        • Physical AI
        • Quantum Computing
        • Security
      • Applications
        • Robotics Solutions Stack
        • Holoscan Sensor Bridge
        • Video Solutions Stack
    • Download & License Center
      • FPGA Development Tools
        • Quartus Prime Pro
        • Quartus Prime Standard
        • Quartus Prime Lite
        • Quartus II Subscription Edition
        • Quartus II Web Edition
      • Embedded Tools
        • Arm* Development Studio for Altera® SoC FPGA
        • Altera® SoC EDS Pro
        • Altera® SoC EDS Standard
      • Add-On Development Tools
        • HLS IP Gen (Beta)
        • DSP Builder Pro
        • DSP Builder Standard
        • SDK for OpenCL™ Pro
        • SDK for OpenCL™ Standard
        • SDK for OpenCL™ Subscription Edition
        • SDK for OpenCL™ Web Edition
        • FPGA AI Suite
      • Simulation Tools
        • Questa*-Altera® FPGA Edition Pro
        • Questa*-Altera® FPGA Edition Standard
        • ModelSim-Altera® FPGAs Pro
        • ModelSim-Altera® FPGAs Standard
        • Simics® Simulator for Altera® FPGA
      • Utilities
        • Flexlm License Daemons Software
        • Advanced Link Analyzer Pro
        • Advanced Link Analyzer Standard
        • Jam STAPL Player
        • Jam STAPL Byte-Code Player
      • Licensing
        • Self Service License Center
        • Licensing Support Center
    • Design Hubs & Training
      • Design Hubs
        • Agilex 7
        • Agilex 5
        • Agilex 3
        • View all Design Hubs
      • Developer Centers
        • Stratix 10
        • Arria 10
        • Cyclone 10 GX
        • Cyclone 10 LP
        • MAX 10
        • View all Developer Centers
      • Training
        • Training Overview
        • My Learning
        • eLearning Catalog
        • Instructor-Led Training Catalog
        • All Altera FPGA Training
        • Learning Plans
        • How to Begin a Simple FPGA Design
        • How To Videos
    • Example Designs
      • FPGA Developer Site
        • Example Designs
        • Zephyr Drivers
        • Linux Drivers
        • See All
      • Design Store
        • Agilex 7
        • Agilex 5
        • MAX 10
        • See All
    • Documentation
      • All FPGA Documentation
        • By Product Family
        • IP Docs
        • Dev Software Docs
        • Release Notes
        • Application Notes
        • Device Overviews
        • Datasheets
        • Errata/Known Issues
        • User Guides
        • Pin Connection Guidelines
        • Pinouts
        • Package Drawings
    • Design Resources
        • Quartus Support Center
        • Step-by-Step Dev Guidance
        • Example Designs
        • Docs & Resources by Family
        • PCB Resources
        • Package Drawings
        • Pinouts
        • Quality & Reliability
        • Find Boards / Dev Kits
        • Find IP
        • Find Partners
        • Find Knowledge Articles
    • Partners
        • Find Partners
        • Find Offerings
        • About ASAP
        • Join Now
        • Sign In
    View All Design
    • Support
        • Community Forums
        • Knowledge Articles
        • University Program
        • Premier Support
        • Supplier Portal
        • Quality & Reliability
    • About
        • Company Overview
        • Newsroom
        • Events
        • Careers
        • Blogs
        • Management Team
        • Board of Directors
  • Contact Us
Search Icon

Breadcrumb

Hero Banner image

PSIRT Advisory – INTEL-SA-00728

Intel® FPGA SDK for OpenCL™ Intel® Quartus® Prime Pro Software Advisory

Altera Security Advisory:INTEL-SA-00728
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege
Severity rating:Medium
Original release:02/14/2023
Last revised:05/06/2026

 

Summary:
Potential security vulnerabilities in the Intel® FPGA SDK for OpenCL™ Intel® Quartus® Prime Pro software may allow escalation of privilege. Intel is releasing software updates to mitigate these potential vulnerabilities.

Vulnerability Details: 
CVEID: CVE-2022-37329

Description: Uncontrolled search path in some Intel® Quartus® Prime Pro and Standard Edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-34157

Description: Improper access control in the Intel® FPGA SDK for OpenCL™ with Intel® Quartus® Prime Pro Edition software before version 22.1 may allow authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products:
Intel® FPGA SDK for OpenCL™ with Intel® Quartus® Prime Pro Edition software before version 22.1.
Intel® Quartus® Prime Pro Edition software before version 21.3.
Intel® Quartus® Prime Standard Edition software before version 21.1.

 

Recommendations:
Intel recommends updating to the versions below.
Intel® Quartus® Prime Pro Edition software to version 21.3 or later at:

  • https://www.altera.com/products/development-tools/quartus

Intel® Quartus® Prime Standard Edition Design Software to version 21.1 or later at:

  • https://www.altera.com/products/development-tools/quartus 

Intel® FPGA SDK for OpenCL™ Pro Edition to version 22.1 or later at:

  • https://www.altera.com/products/development-tools/quartus

Acknowledgements:
Intel would like to thank Marius Gabriel Mihai CVE-2022-37329,  Intel employee CVE-2022-34157.

RevisionDateDescription
1.002/14/2023Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00715

Intel® Advanced Link Analyzer Advisory

Altera Security Advisory:INTEL-SA-00715
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege
Severity rating:Medium
Original release:11/08/2022
Last revised:05/06/2026

 

Summary:
A potential security vulnerability in the Intel® Advanced Link Analyzer Pro and Standard edition software may allow escalation of privilege.  Intel is releasing software updates to mitigate this potential vulnerability.

Vulnerability Details: 
CVEID: CVE-2022-27638

Description: Uncontrolled search path element in the Intel® Advanced Link Analyzer Pro before version 22.2 and Standard edition software before version 22.1.1 STD may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products:
Intel® Advanced Link Analyzer Pro edition software before version 22.2.
Intel® Advanced Link Analyzer Standard edition software before version 22.1.1 STD.

 

Recommendations:
Intel recommends updating the Intel® Advanced Link Analyzer Pro edition software to version 22.2 or later.
Intel recommends updating the Intel® Advanced Link Analyzer Standard edition software to version 22.1.1 STD or later.

Updates are available for download at these locations:

  • https://www.altera.com/products/development-tools/quartus 

Acknowledgements:
Intel would like to thank Amin Saidani for reporting this issue.

RevisionDateDescription
1.011/08/2022Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00714

Intel® Quartus® Advisory

Altera Security Advisory:INTEL-SA-00714
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege, Information Disclosure
Severity rating:High
Original release:02/14/2023
Last revised:05/06/2026

 

Summary:
Potential security vulnerabilities in the Intel® Quartus® Prime Pro and Standard edition software may allow escalation of privilege or information disclosure.  Intel is releasing software updates to mitigate these potential vulnerabilities.

Vulnerability Details: 
CVEID: CVE-2022-33892

Description: Path traversal in the Intel® Quartus® Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 7.3 High

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-33902

Description: Insufficient control flow management in the Intel® Quartus® Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 7.3 High

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-26840

Description: Improper neutralization in the Intel® Quartus® Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 7.3 High

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-32570

Description: Improper authentication in the Intel® Quartus® Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-26888

Description: Cross-site scripting in the Intel® Quartus® Prime Pro and Standard edition software may allow an authenticated user to potentially enable information disclosure via local access.

CVSS Base Score: 2.8 Low

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Affected products:
Intel® Quartus® Prime Pro edition software before version 22.2.
Intel® Quartus® Prime Standard edition software before version 22.1STD.

 

Recommendations:
Intel recommends updating the Intel® Quartus® Prime Pro edition software to version 22.2 or later.
Intel recommends updating the Intel® Quartus® Prime Standard edition software to version 22.1STD or later.

Updates are available for download at these locations:

  • https://www.altera.com/products/development-tools/quartus

Acknowledgements:
These issues were found externally.  Intel would like to thank Julien Ahrens from RCE Security (CVE-2022-33892, CVE-2022-33902, CVE-2022-26840, CVE-2022-26888) for reporting these issues.

RevisionDateDescription
1.002/14/2023Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00672

Intel® Enpirion® Digital Power Configurator GUI Advisory

Altera Security Advisory:INTEL-SA-00672
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege
Severity rating:Medium
Original release:08/09/2022
Last revised:05/06/2026

 

Summary:
A potential security vulnerability in the Intel® Enpirion® Digital Power Configurator GUI software may allow escalation of privilege. Intel is not releasing updates to mitigate this potential vulnerability and has issued a Product Discontinuation Notice for the Intel® Enpirion® Digital Power Configurator GUI software.

Vulnerability Details: 
CVEID: CVE-2022-25999

Description: Uncontrolled search path element in the Intel® Enpirion® Digital Power Configurator GUI software, all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector:  CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products:
Intel® Enpirion® Digital Power Configurator GUI software, all versions.

 

Recommendations:
Intel has issued a Product Discontinuation notice for the Intel® Enpirion® Digital Power ConfiguratorGUI software and recommends that users of the Intel® Enpirion® Digital Power Configurator GUI software uninstall it or discontinue use at their earliest convenience.

Possible Alternative Workarounds - Intel recommends creating the following directory on the system Intel® Enpirion® Digital Power Configurator is installed: C:\Qt\5.12.9\. And modifying the directory permissions to only allow the following permissions: “Read”, “List folder contents” and “Read & execute” to all users, and only allowing Administrators and trusted account full control.
 

Acknowledgements:
Intel would like to thank Marius Gabriel Mihai for reporting this issue.

RevisionDateDescription
1.008/09/2022Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00659

Intel® Quartus® Advisory

Altera Security Advisory:INTEL-SA-00659
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege, Information Disclosure
Severity rating:Medium
Original release:11/08/2022
Last revised:05/06/2026

 

Summary:
Potential security vulnerabilities in the Intel® Quartus® Prime Pro and Standard edition software may allow escalation of privilege or information disclosure. Intel is releasing software updates to mitigate these potential vulnerabilities.

Vulnerability Details: 
CVEID: CVE-2022-27187

Description: Uncontrolled search path element in the Intel® Quartus® Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-27233

Description: XML injection in the Quartus® Prime Programmer included in the Intel® Quartus® Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.

CVSS Base Score: 6.5 Medium

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products:
Intel® Quartus® Prime Programmer Pro edition software before version 22.1.
Intel® Quartus® Prime Programmer Standard edition software before version 21.1 Patch 0.02std.
Intel® Quartus® Prime Pro edition software before version 22.1.
Intel® Quartus® Prime Standard edition software before version 21.1 Patch 0.02std.
 

Recommendations:
Intel recommends updating the Intel® Quartus® Prime Pro edition software to version 22.1 or later.
Intel recommends updating the Intel® Quartus® Prime Standard edition software to version 21.1 Patch 0.02std or later.

Updates are available for download at these locations:

  • https://www.altera.com/products/development-tools/quartus
     

Acknowledgements:
Intel would like to thank Julien Ahrens from RCE Security (CVE-2022-27187) for reporting this issue.

RevisionDateDescription
1.011/08/2022Initial Release
1.102/06/2023Updated CVE-2022-27233 product version.
1.203/02/2023Updated Acknowledgements
1.303/10/2023Updated Acknowledgements
1.405/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00632

Intel® Quartus® Advisory

Altera Security Advisory:INTEL-SA-00632
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege, Denial of Service, Information Disclosure
Severity rating:High
Original release:02/08/2022
Last revised:05/06/2026

 

Summary:
Potential security vulnerabilities in Intel® Quartus® Prime Pro and Standard Editions may allow escalation of privilege, denial of service, or information disclosure. Intel is releasing software updates to mitigate these potential vulnerabilities.

Vulnerability Details: 
CVEID: CVE-2022-21203

Description: Improper permissions in the SafeNet Sentinel driver for Intel® Quartus® Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 8.8 High

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVEID: CVE-2021-44454

Description: Improper input validation in a third-party component for Intel® Quartus® Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 7.3 High

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-21220

Description: Improper restriction of XML external entity for Intel® Quartus® Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-21204

Description: Improper permissions for Intel® Quartus® Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-21174

Description: Improper access control in a third-party component of Intel® Quartus® Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVEID: CVE-2022-21205

Description: Improper restriction of XML external entity reference in DSP Builder Pro for Intel® Quartus® Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVSS Base Score: 6.5 Medium

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products:
Intel® Quartus® Prime Pro Edition before version 21.3.
Intel® Quartus® Prime Standard Edition before version 21.1.
 

Recommendations:
Intel recommends updating Intel® Quartus® Prime Pro Edition to version 21.3 or later.
Intel recommends updating Intel® Quartus® Prime Standard Edition to version 21.1 or later.

Updates are available for download at these locations:

  • https://www.altera.com/products/development-tools/quartus
     

Acknowledgements:
These issues were found externally. Intel would like to thank Marius Gabriel Mihai (CVE-2022-21204 and CVE-2022-21174) for reporting these issues.

RevisionDateDescription
1.002/08/2022Initial Release
1.102/15/2022Corrected the reporter's name
1.203/10/2023Updated Acknowledgements
1.305/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00451

Intel® Quartus® Prime Advisory

Altera Security Advisory:INTEL-SA-00451
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege
Severity rating:Medium
Original release:02/09/2021
Last revised:05/06/2026

 

Summary:
A potential security vulnerability in the Intel® Quartus® Prime Pro and Standard edition software may allow escalation of privilege. Intel is releasing software updates to mitigate this potential vulnerability.

Vulnerability Details: 
CVEID: CVE-2020-24481

Description: Insecure inherited permissions for the Intel® Quartus® Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 6.7 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products:
Intel® Quartus® Prime Pro Edition before version 20.4.
Intel® Quartus® Prime Standard Edition before version 20.1.
 

Recommendations:
Intel recommends updating Intel® Quartus® Prime Pro Edition to version 20.4 or later.
Intel recommends updating Intel® Quartus® Prime Standard Edition to version 20.1 or later.

Updates are available for download at these locations:

  • https://www.altera.com/products/development-tools/quartus
     

Acknowledgements:
Intel would like to thank Marius Gabriel Mihai for reporting this issue.

RevisionDateDescription
1.002/09/2021Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00446

Intel® Quartus® Prime Advisory

Altera Security Advisory:INTEL-SA-00446
Advisory Category:Software
Impact of vulnerability:Information Disclosure
Severity rating:Medium
Original release:11/10/2020
Last revised:05/06/2026

 

Summary:
A potential security vulnerability in Intel® Quartus® Prime may allow information disclosure. Intel is releasing software updates to mitigate this potential vulnerability.

Vulnerability Details: 
CVEID: CVE-2020-24454

Description: Improper Restriction of XML External Entity Reference in subsystem for Intel® Quartus® Prime Pro Edition before version 20.3 and Intel® Quartus® Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via network access.

CVSS Base Score:  6.5 Medium

CVSS Vector:  CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products:
Intel® Quartus® Prime Pro before version 20.3.
Intel® Quartus® Prime Standard before version 20.1 Update1.
 

Recommendations:
Intel recommends updating Intel® Quartus® Prime Pro to 20.3 or later and Intel® Quartus® Prime Standard to 20.1 Update1 or later.

Intel® Quartus® Prime Pro updates are available for download at this location:

  • https://www.altera.com/products/development-tools/quartus

Intel® Quartus® Prime Standard updates are available for download at these locations:

  • http://download.altera.com/akdlm/software/acs/20.1std/0.06std/quartus-20.1std-0.06std-linux.run
  • http://download.altera.com/akdlm/software/acs/20.1std/0.06std/quartus-20.1std-0.06std-windows.exe

 

Acknowledgements:
Intel would like to thank Oussama Sahnoun for reporting this issue.

RevisionDateDescription
1.011/10/2020Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00440

Intel® FPGA OPAE Driver Advisory

Altera Security Advisory:INTEL-SA-00440
Advisory Category:Software
Impact of vulnerability:Escalation of Privilege
Severity rating:High
Original release:06/08/2021
Last revised:05/06/2026

 

Summary:
A potential security vulnerability in the Intel® Field Programmable Gate Array (FPGA) Open Programmable Acceleration Engine (OPAE) driver for Linux may allow escalation of privilege.  Intel is releasing software updates to mitigate this potential vulnerability.

Vulnerability Details: 
CVEID: CVE-2020-24485

Description: Improper conditions check in the Intel® FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Base Score: 7.8 High

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products:
Intel® FPGA OPAE drivers found in the Linux Kernel before version 4.17. The following products are impacted:

  • Intel® FPGA PAC D5005, Intel® Acceleration Stack v2.0.1
  • Intel® PAC with Arria® 10 GX FPGA, Intel® Acceleration Stack v1.2.1
  • Intel® Acceleration Stack Version 1.1 for the Intel® FPGA Pac N3000-N
  • Intel® Acceleration Stack Version 1.3 for the Intel® FPGA PAC N3000
  • Intel® Acceleration Stack Version 1.2 for the Intel® FPGA PAC N3000-V
     

Recommendations:
Intel recommends updating the Intel® FPGA OPAE driver for Linux to the versions indicated below or later:

  • Intel® FPGA PAC D5005, Intel® Acceleration Stack v2.0.1
  • Intel® FPGA Programmable Acceleration Card D5005 - Getting Started , See Update 2.
  • opae-intel-fpga-driver-2.0.2-2.x86_64.rpm
  • Intel® PAC with Arria® 10 GX FPGA, Intel® Acceleration Stack v1.2.1
  • Intel® Programmable Acceleration Card with Intel Arria® 10 GX FPGA - Getting Started , See Update 1.
  • opae-intel-fpga-driver-2.0.3-4.x86_64.rpm
  • Intel® Acceleration Stack Version 1.1 for the Intel® FPGA Pac N3000-N
  • Update for 1.1
  • n3000_patch_1.1.2.tar.gz
  • Intel® Acceleration Stack Version 1.3 for the Intel® FPGA PAC N3000
  • Update for 1.3
  • N3000_1.2.0.2 Patch
  • Intel® Acceleration Stack Version 1.2 for the Intel® FPGA PAC N3000-V
  • AFU Developers update .
  • n3000/n3000_ias_1_3_1_pv_dev_centos_installer.tar.gz
  • Non-AFU Development CentOS 7.6 update .
  • n3000_ias_1_3_1_pv_rte_centos_installer.tar.gz
  • Non-AFU Development RHEL 8.2 update .
  • n3000_ias_1_3_1_pv_rte_RHEL_installer.tar.gz
     

Acknowledgements:
The following issue was found internally by Intel employees.  Intel would like to thank Thierry Fernandes Faria and Chun Feng.

RevisionDateDescription
1.006/08/2021Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Hero Banner image

PSIRT Advisory – INTEL-SA-00400

Intel® 50GbE IP Core for Intel® Quartus® Prime Networking Advisory

Altera Security Advisory:INTEL-SA-00400
Advisory Category:Software
Impact of vulnerability:Denial of Service
Severity rating:Medium
Original release:11/10/2020
Last revised:05/06/2026

 

Summary:
A potential security vulnerability in the Intel® 50 Gbps Ethernet (50GbE) Intellectual Property (IP) Core for Intel® Quartus® Prime may allow denial of service.Intel is releasing a software update to mitigate this potential vulnerability.

Vulnerability Details: 
CVEID: CVE-2020-8767

Description: Uncaught exception in the Intel(R) 50GbE IP Core for Intel® Quartus® Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access.

CVSS Base Score: 4.4 Medium

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H

Affected products:
Intel® Quartus® Prime before version 20.2.

Recommendations:
Intel recommends updating Intel® Quartus® Prime to 20.2 or later and discontinuing use of the Intel® 50GbE IP Core.  The Intel® 100GbE IP Core is a recommended alternative.

Acknowledgements:
This issue was found internally by Intel employees.  Intel we would like to thank Shahram Jamshidi.

RevisionDateDescription
1.011/10/2020Initial Release
1.105/06/2026Transfer Advisory to Altera.

 

 

Legal Notices and Disclaimers

Altera provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice.   

Altera products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Altera products that have met their End of Servicing Updates may no longer receive functional and security updates.   

Altera technologies’ features and benefits depend on system configuration and may require enabled hardware, software, or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at https://www.altera.com.   

Some results may have been estimated or simulated using internal Altera analysis or architecture simulation or modeling and are provided for informational purposes only. Any differences in your system hardware, software, or configuration may affect your actual performance. © Altera Corporation.   

Altera, the Altera logo, and other Altera marks are trademarks of Altera Corporation in the United States and other countries. Other names and brands may be claimed as the property of others.  

Pagination

  • Previous page ‹‹
  • Page 4
  • Next page ››
Subscribe to Security
footerbackground
site-footer-logo
Products
  • FPGA, SoCs, CPLD’s
  • Development Software & Tools
  • Development Kits
  • Intellectual Property
Design
  • Download Center
  • Self Service Licensing Center
  • Design Hub
  • Documentation
  • Training
  • Design Examples
  • Design Resources
  • Partner Network
Support
  • Community Forum
  • Premier Support
  • Knowledge Articles
  • Quality & Reliability
  • University Program
About
  • Company Overview
  • Newsroom
  • Careers
© Altera Corporation Terms of Use Privacy Policy Cookies Trademarks PSIRT