Home

Description

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1 through 24.1; Quartus Prime Lite: from 19.1 through 24.1.

PUBLISHED Reserved 2025-12-12 | Published 2026-01-06 | Updated 2026-01-28 | Assigner Altera




MEDIUM: 5.4CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

MEDIUM: 6.7CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-427 Uncontrolled Search Path Element

Product status

Default status
unaffected

19.1 (custom)
affected

Default status
unaffected

19.1 (custom)
affected

References

www.altera.com/security/security-advisory/asa-0005

community.altera.com/...os®-ii-command-shell-utility/350185

cve.org (CVE-2025-14625)

nvd.nist.gov (CVE-2025-14625)

Download JSON