CVE-2023-28396: Medium severity Intel Thunderbolt Controllers vulnerability
Published Feb 14, 2024
·Updated
Improper access control in firmware for some Intel(R) Thunderbol(TM) Controllers versions before 41 may allow a privileged user to enable denial of service via local access.
Affected Software
3 affected components
Intel Thunderbolt Controllers<41
All of the following
Intel Jhl8440 Firmware<41
Intel Jhl8440
Event History
Feb 14, 2024
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-28396?
CVE-2023-28396 has a high severity rating due to improper access control that can lead to denial of service.
2
How do I fix CVE-2023-28396?
To fix CVE-2023-28396, update the Intel Thunderbolt Controllers firmware to version 41 or later.
3
What versions are affected by CVE-2023-28396?
CVE-2023-28396 affects Intel Thunderbolt Controllers firmware versions prior to 41.
4
What kind of vulnerability is CVE-2023-28396?
CVE-2023-28396 is classified as an improper access control vulnerability.
5
Who is impacted by CVE-2023-28396?
Privileged users with local access to systems running affected versions of Intel Thunderbolt Controllers are impacted by CVE-2023-28396.