CVE-2020-12295: Input Validation
Improper input validation in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12295?
CVE-2020-12295 is a vulnerability that involves improper input validation in some Intel(R) Thunderbolt(TM) controllers.
How does CVE-2020-12295 affect Intel Thunderbolt controllers?
CVE-2020-12295 allows an authenticated user to potentially enable denial of service via local access on affected Thunderbolt controllers.
Which Intel Thunderbolt controllers are affected by CVE-2020-12295?
CVE-2020-12295 affects Intel Thunderbolt controllers including Jhl6240 Thunderbolt 3 Firmware, Jhl6340 Thunderbolt 3 Firmware, Jhl6540 Thunderbolt 3 Firmware, Jhl7040 Thunderbolt 3 Retimer Firmware, Jhl7340 Thunderbolt 3 Firmware, Jhl7440 Thunderbolt 3 Firmware, Jhl7540 Thunderbolt 3 Firmware, Jhl8010r Usb Retimer Firmware, Dsl5320 Thunderbolt 2 Firmware, Dsl5520 Thunderbolt 2 Firmware, Dsl6340 Thunderbolt 3 Firmware, Dsl6540 Thunderbolt 3 Firmware, and Jhl8040r Thunderbolt 4 Retimer Firmware.
What is the severity of CVE-2020-12295?
CVE-2020-12295 has a severity rating of 5.5 (medium).
Where can I find more information about CVE-2020-12295?
More information about CVE-2020-12295 can be found on the Intel Security Center Advisory page: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00401.html