PT-2015-5904 · Freedesktop.Org+1 · Avahi+1

·

CVE-2015-2809

·

Published

2015-04-01

·

Updated

2025-12-03

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology DiskStation Manager (DSM) versions prior to 3.1
Description The issue allows remote attackers to cause a denial of service or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component. This is due to the Multicast DNS (mDNS) responder inadvertently responding to unicast queries with source addresses that are not link-local.
Recommendations For versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to port 5353 to minimize the risk of exploitation.

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2809

Affected Products

Avahi
Synology Diskstation Manager