CVE-2020-12321
published 2020-11-12CVE-2020-12321: Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable…
PriorityP345high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.97%
58.0th percentile
Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | dual_band_wireless-ac_3165_firmware | < 21.110 | 21.110 |
| intel | dual_band_wireless-ac_3168_firmware | < 21.110 | 21.110 |
| intel | dual_band_wireless-ac_8260_firmware | < 21.110 | 21.110 |
| intel | dual_band_wireless-ac_8265_firmware | < 21.110 | 21.110 |
| intel | wi-fi_6_ax200_firmware | < 21.110 | 21.110 |
| intel | wi-fi_6_ax201_firmware | < 21.110 | 21.110 |
| intel | wireless-ac_9260_firmware | < 21.110 | 21.110 |
| intel | wireless-ac_9461_firmware | < 21.110 | 21.110 |
| intel | wireless-ac_9462_firmware | < 21.110 | 21.110 |
| intel | wireless-ac_9560_firmware | < 21.110 | 21.110 |
| intel | wireless_7265_firmware | < 21.110 | 21.110 |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
hardware: buffer overflow in bluetooth firmware
vendor_redhat·2020-11-10·CVSS 8.8
CVE-2020-12321 [HIGH] CWE-120 hardware: buffer overflow in bluetooth firmware
hardware: buffer overflow in bluetooth firmware
Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
A flaw was found in the firmware of some Intel Bluetooth devices. This may allow an unauthenticated attacker within Bluetooth range to overflow a buffer and corrupt memory leading to a crash or privilege escalation.
Mitigation: To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how to disable Bluetooth modules are available on the Custome
GHSA
GHSA-mmx9-f32w-9hqf: Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21
ghsa_unreviewed·2022-05-24
CVE-2020-12321 [HIGH] CWE-119 GHSA-mmx9-f32w-9hqf: Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21
Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
No detection rules found.
No public exploits indexed.
Checkpoint
16th November – Threat Intelligence Bulletin
blogs_checkpoint·2020-11-16
CVE-2020-16013 16th November – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th November – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 16th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has further investigated the newly revealed ‘Pay2Key’ ransomware, tracing several ransom payments to an Iranian cryptocurrency exchange, and concluded that the malware, which focuses on Israeli organizations, is most likely of Iranian origin.
Check Point SandBlast Agent provides protection agains
Bugzilla
CVE-2020-12321 hardware: buffer overflow in bluetooth firmware
bugzilla·2020-11-02·CVSS 8.8
CVE-2020-12321 [HIGH] CVE-2020-12321 hardware: buffer overflow in bluetooth firmware
CVE-2020-12321 hardware: buffer overflow in bluetooth firmware
A flaw was found in the firmware of some Intel bluetooth devices. This may allow an unauthenticated attacker within bluetooth range to overflow a buffer and corrupt memory leading to a crash or privilege escalation.
Limited information is available about this flaw, it is believed it affects all firmware releases prior to 21.110
Discussion:
External References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00403.html
---
Mitigation:
To mitigate these vulnerabilities on the operating system level, disable the Bluetooth functionality via blocklisting kernel modules in the Linux kernel. The kernel modules can be prevented from being loaded by using system-wide modprobe rules. Instructions on how
2020-11-12
Published