Improper access control in Intel products - CVE-2020-12290

 

Improper access control in Intel products - CVE-2020-12290

Published: June 15, 2021


Vulnerability identifier: #VU54122
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12290
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions and perform a denial of service (DoS) attack.


Affected software

Intel Thunderbolt DSL5520
Intel Thunderbolt DSL5320
Intel Thunderbolt DSL6340
Intel Thunderbolt DSL6540
Intel Thunderbolt JHL6240
Intel Thunderbolt JHL7040
Intel Thunderbolt JHL8040R
Intel Thunderbolt JHL8010R
Intel Thunderbolt JHL6540
Intel Thunderbolt JHL6340
Intel Thunderbolt JHL7540
Intel Thunderbolt JHL7340
Intel Thunderbolt JHL7440

How to mitigate CVE-2020-12290

Install updates from vendor's website.

Intel Thunderbolt JHL6240 - update to 21
Intel Thunderbolt JHL7040 - update to 22
Intel Thunderbolt JHL8040R - update to 41
Intel Thunderbolt JHL8010R - update to 41
Intel Thunderbolt JHL6540 - update to 46
Intel Thunderbolt JHL6340 - update to 46
Intel Thunderbolt JHL7540 - update to 60
Intel Thunderbolt JHL7340 - update to 60
Intel Thunderbolt JHL7440 - update to 60

External References

Related Security Bulletins