CVE-2012-2313

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 13 Jun 2012, 10:00
Last modified:06 Aug 2024, 19:26

Vulnerability Summary

Overall Risk (default)
low
15/100
CVSS Score
1.2 LOW
v2.0 (nvd)
EPSS Score
0.17% LOW
0% probability -0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

13 Jun 2012, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 19:26
Last Modified
Vulnerability information updated

Description

The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.

CVSS Metrics

  • v2.0LOWScore: 1.2AV:L/AC:H/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.17% Percentile: 38%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • linuxlinux_kernel

    ≤ 3.3.6 | 3.3 | 3.3:rc1 | 3.3:rc2 | 3.3:rc3 | 3.3:rc4 | 3.3:rc5 | 3.3:rc6 | 3.3:rc7 | 3.3.1 | 3.3.2 | 3.3.3 | 3.3.4 | 3.3.5

  • novellsuse_linux_enterprise_server

    10.0:sp4

  • redhatenterprise_linux

    5

  • redhatenterprise_linux_desktop

    5.0

  • redhatenterprise_linux_eus

    5.6.z

  • redhatenterprise_linux_long_life

    5.6

  • redhatenterprise_linux_server_aus

    6.2

  • redhatenterprise_linux_server_eus

    6.1.z | 6.2.z

References (12)