Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2023-49614 |
CWE-ID | CWE-787 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Intel Agilex 7 FPGA and SoC FPGA Hardware solutions / Firmware Intel Stratix 10 FPGA and SoC FPGA Hardware solutions / Firmware Intel Field Programmable Gate Array (FPGA) Hardware solutions / Firmware |
Vendor | Intel |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU89739
Risk: Low
CVSSv3.1: 4.9 [CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-49614
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
DescriptionThe vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A local administrator can trigger an out-of-bounds write and gain access to sensitive information or escalate privileges on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel Agilex 7 FPGA and SoC FPGA: All versions
Intel Stratix 10 FPGA and SoC FPGA: All versions
Intel Field Programmable Gate Array (FPGA): before 2.9.0
CPE2.3http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01050.html
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.