SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-2809

The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic…

MEDIUM 5.0EPSS 3.55%

Does this matter?

Lower severity and a low EPSS score (3.55%). Track it; it rarely justifies an emergency change on its own.

Description

The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.55% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
synology/diskstation manager
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.