First published: Wed Jun 09 2021(Updated: )
Out-of-bounds write in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel jhl6240 Thunderbolt 3 | <21 | |
Intel JHL6240 Thunderbolt 3 | ||
Intel JHL6340 Firmware | <46 | |
Intel JHL6340 | ||
Intel JHL6540 Thunderbolt 3 | <46 | |
Intel JHL6540 Thunderbolt 3 | ||
Intel JHL7040 Thunderbolt 3 Retimer Firmware | <22 | |
Intel JHL7040 Thunderbolt 3 Retimer Firmware | ||
Intel JHL7340 Firmware | <60 | |
Intel JHL7340 | ||
Intel JHL7440 Thunderbolt 3 | <60 | |
Intel JHL7440 | ||
Intel Jhl7540 Firmware | <60 | |
Intel Jhl7540 Thunderbolt 3 | ||
Intel JHL8010R USB Retimer | <41 | |
Intel JHL8010r USB Retimer Firmware | ||
Intel DSL5320 Thunderbolt 2 | ||
Intel DSL5320 Thunderbolt 2 Firmware | ||
Intel DSL5520 Thunderbolt 2 Firmware | ||
Intel DSL5520 Thunderbolt 2 Firmware | ||
Intel DSL6340 Thunderbolt 3 firmware | ||
Intel DSL6340 Thunderbolt 3 firmware | ||
Intel DSL6540 Thunderbolt 3 | ||
Intel DSL6540 Thunderbolt 3 | ||
Intel JHL8040R Thunderbolt 4 Retimer | <41 | |
Intel JHL8040R Thunderbolt 4 Retimer Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12289 refers to an out-of-bounds write vulnerability in some Intel Thunderbolt controllers that may allow an authenticated user to potentially enable denial of service via local access.
The vulnerability affects certain versions of Intel Thunderbolt controllers.
The severity of CVE-2020-12289 is medium with a CVSS score of 5.5.
An authenticated user can exploit CVE-2020-12289 by performing an out-of-bounds write on affected Intel Thunderbolt controllers.
Yes, Intel has provided a fix for CVE-2020-12289. It is recommended to update to the latest firmware versions for the affected Intel Thunderbolt controllers.