Knowledge Base Article

How to mitigate the security vulnerability in the Nios® II Command Shell utility?

Description

Due to a problem in the Quartus® Prime Standard and Lite Edition Software version 19.1 through 24.1, the Nios® II Command Shell utility included in the Quartus® Prime Software for Windows* is vulnerable to a Current Working Directory (CWD) planting attack. The Linux* versions are not affected.

Resolution

To work around this problem, replace the “Nios II Command Shell.bat” Windows Batch File located in the <drive>:\<edition>\<version number>\nios2eds\, with the attached file below.

This problem is fixed beginning with the Quartus® Prime Standard and Lite Edition Software version 25.1.

Updated 1 day ago
Version 3.0
No CommentsBe the first to comment