cbcvebase.
CVE-2012-2313
published 2012-06-13

CVE-2012-2313: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows…

PriorityP410low1.2CVSS 2.0
AVLACHAuNCNINAP
EPSS
0.56%
42.6th percentile
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.2.19-1 (bookworm)linux 3.2.19-1 (bookworm)
linuxlinux_kernel<= 3.3.6
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
linuxlinux_kernel>= 0 < 3.2.19-13.2.19-1
novellsuse_linux_enterprise_server
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_long_life
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus

CVSS provenance

nvdv2.01.2LOWAV:L/AC:H/Au:N/C:N/I:N/A:P
osv1.2LOW
vendor_ubuntu4.9MEDIUM
vendor_debian1.2LOW
vendor_redhat1.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.