CVE-2020-12289: Intel DSL5320 Thunderbolt 2 Firmware

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Out-of-bounds write in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

Affected products

  • Intel DSL5320 Thunderbolt 2 Firmware: any version
  • Intel DSL5520 Thunderbolt 2 Firmware: any version
  • Intel DSL6340 Thunderbolt 3 Firmware: any version
  • Intel DSL6540 Thunderbolt 3 Firmware: any version
  • Intel JHL6240 Thunderbolt 3 Firmware: before 21 (fixed in 21)
  • Intel JHL6340 Thunderbolt 3 Firmware: before 46 (fixed in 46)
  • Intel JHL6540 Thunderbolt 3 Firmware: before 46 (fixed in 46)
  • Intel JHL7040 Thunderbolt 3 Retimer Firmware: before 22 (fixed in 22)
  • Intel JHL7340 Thunderbolt 3 Firmware: before 60 (fixed in 60)
  • Intel JHL7440 Thunderbolt 3 Firmware: before 60 (fixed in 60)
  • Intel JHL7540 Thunderbolt 3 Firmware: before 60 (fixed in 60)
  • Intel JHL8010R USB Retimer Firmware: before 41 (fixed in 41)
  • Intel JHL8040R Thunderbolt 4 Retimer Firmware: before 41 (fixed in 41)

Published 2021-06-09. Last modified 2026-06-17.