CVE-2015-2809: Infoleak
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2809?
CVE-2015-2809 is considered to have a medium severity rating due to its potential for causing denial of service.
How do I fix CVE-2015-2809?
To fix CVE-2015-2809, users should upgrade to Synology DiskStation Manager version 3.1 or later.
What type of attacks can be performed using CVE-2015-2809?
CVE-2015-2809 can be exploited for denial of service attacks or to obtain sensitive information through traffic amplification.
Which versions of Synology DiskStation Manager are affected by CVE-2015-2809?
CVE-2015-2809 affects all versions of Synology DiskStation Manager prior to version 3.1.
Is CVE-2015-2809 relevant for all Synology devices?
CVE-2015-2809 is relevant for devices running Synology DiskStation Manager versions before 3.1.