Input validation error in Intel products - CVE-2020-12294

 

Input validation error in Intel products - CVE-2020-12294

Published: June 15, 2021


Vulnerability identifier: #VU54117
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12294
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient control flow management. A local user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Intel Thunderbolt DSL5520
Intel Thunderbolt DSL5320
Intel Thunderbolt DSL6340
Intel Thunderbolt DSL6540
Intel Thunderbolt JHL6240
Intel Thunderbolt JHL7040
Intel Thunderbolt JHL8040R
Intel Thunderbolt JHL8010R
Intel Thunderbolt JHL6540
Intel Thunderbolt JHL6340
Intel Thunderbolt JHL7540
Intel Thunderbolt JHL7340
Intel Thunderbolt JHL7440

How to mitigate CVE-2020-12294

Install updates from vendor's website.

Intel Thunderbolt JHL6240 - update to 21
Intel Thunderbolt JHL7040 - update to 22
Intel Thunderbolt JHL8040R - update to 41
Intel Thunderbolt JHL8010R - update to 41
Intel Thunderbolt JHL6540 - update to 46
Intel Thunderbolt JHL6340 - update to 46
Intel Thunderbolt JHL7540 - update to 60
Intel Thunderbolt JHL7340 - update to 60
Intel Thunderbolt JHL7440 - update to 60

External References

Related Security Bulletins