Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wgcg-8h66-7wvp

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.

The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.

EPSS

Процентиль: 82%
0.01716
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 11 лет назад

The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.

EPSS

Процентиль: 82%
0.01716
Низкий

Дефекты

CWE-200