CVE-2020-12290 describes an improper access control vulnerability in specific Intel Thunderbolt controllers. An authenticated local user could exploit this flaw to potentially cause a denial of service. Rated 5.5 MEDIUM on the CVSS scale, this vulnerability requires local access and user authentication, but no user interaction. Its primary impact is limited to availability, meaning data confidentiality and integrity are not directly affected. There is no evidence of active exploitation, nor are there any public exploit codes or Metasploit modules available. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21CPE matchmatch criteria | cpe:2.3:o:intel:jhl6240_thunderbolt_3_firmware:*:*:*:*:*:*:*:* | ||
< 46CPE matchmatch criteria | cpe:2.3:o:intel:jhl6340_thunderbolt_3_firmware:*:*:*:*:*:*:*:* | ||
< 46CPE matchmatch criteria | cpe:2.3:o:intel:jhl6540_thunderbolt_3_firmware:*:*:*:*:*:*:*:* | ||
< 22CPE matchmatch criteria | cpe:2.3:o:intel:jhl7040_thunderbolt_3_retimer_firmware:*:*:*:*:*:*:*:* | ||
< 60CPE matchmatch criteria | cpe:2.3:o:intel:jhl7340_thunderbolt_3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.