Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 21:30:00 +0000

Type Values Removed Values Added
Description Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.
Title Quartus Prime Pro Edition Advisory
First Time appeared Altera
Altera quartus Prime Pro
Weaknesses CWE-427
CPEs cpe:2.3:a:altera:quartus_prime_pro:*:*:windows:*:*:*:*:*
Vendors & Products Altera
Altera quartus Prime Pro
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Altera

Published:

Updated: 2026-01-07T16:55:28.143Z

Reserved: 2025-12-12T19:11:15.340Z

Link: CVE-2025-14605

cve-icon Vulnrichment

Updated: 2026-01-07T16:55:24.860Z

cve-icon NVD

Status : Received

Published: 2026-01-07T02:02:59.913

Modified: 2026-01-07T02:02:59.913

Link: CVE-2025-14605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses