CVE-2020-12296: Medium severity intel dsl5320 thunderbolt 2 vulnerability
Published Jun 9, 2021
·Updated
Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.
Affected Software
26 affected components
Intel DSL5320 Thunderbolt 2
Intel DSL5320 Thunderbolt 2 Firmware
Intel DSL5520 Thunderbolt 2 Firmware
Intel DSL5520 Thunderbolt 2 Firmware
Intel DSL6340 Thunderbolt 3 firmware
Intel DSL6340 Thunderbolt 3 firmware
Intel DSL6540 Thunderbolt 3
Intel DSL6540 Thunderbolt 3
Intel jhl6240 Thunderbolt 3<21
Intel JHL6240 Thunderbolt 3
Intel JHL6340 Firmware<46
Intel JHL6340
Intel JHL6540 Thunderbolt 3<46
Intel JHL6540 Thunderbolt 3
Intel JHL7040 Thunderbolt 3 Retimer Firmware<22
Intel JHL7040 Thunderbolt 3 Retimer Firmware
Intel JHL7340 Firmware<60
Intel JHL7340
Intel JHL7440 Thunderbolt 3<60
Intel JHL7440
Intel Jhl7540 Firmware<60
Intel Jhl7540 Thunderbolt 3
Intel JHL8010R USB Retimer<41
Intel JHL8010r USB Retimer Firmware
Intel JHL8040R Thunderbolt 4 Retimer<41
Intel JHL8040R Thunderbolt 4 Retimer Firmware
Event History
Jun 9, 2021
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-12296?
CVE-2020-12296 is a vulnerability that allows an authenticated user to potentially enable denial of service via local access in some Intel(R) Thunderbolt(TM) controllers.
2
Is Intel Dsl5320 Thunderbolt 2 firmware affected by CVE-2020-12296?
No, Intel Dsl5320 Thunderbolt 2 firmware is not vulnerable to CVE-2020-12296.
3
How can an authenticated user exploit CVE-2020-12296?
An authenticated user can potentially enable denial of service through local access.
4
What is the severity level of CVE-2020-12296?
CVE-2020-12296 has a severity level of medium.
5
Where can I find more information about CVE-2020-12296?
You can find more information about CVE-2020-12296 at the following link: [Intel Security Advisory Intel-SA-00401](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00401.html).