PT-2015-5904 · Freedesktop.Org+1 · Avahi+1

Chad Seaman

·

Published

2015-04-01

·

Updated

2025-12-03

·

CVE-2015-2809

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology DiskStation Manager (DSM) versions prior to 3.1
Description The issue allows remote attackers to cause a denial of service or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component. This is due to the Multicast DNS (mDNS) responder inadvertently responding to unicast queries with source addresses that are not link-local.
Recommendations For versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to port 5353 to minimize the risk of exploitation.

Fix

DoS

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2015-2809

Affected Products

Avahi
Synology Diskstation Manager