CVE-2024-52615

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 21, 2024
CWE ID 330

Summary

CVE-2024-52615 is a newly identified vulnerability affecting the Avahi-daemon software. This issue stems from Avahi's reliance on fixed source ports for wide-area DNS queries, making it simpler for cyber attackers to inject malicious DNS responses. If exploited, this vulnerability could potentially lead to DNS spoofing, redirecting users to malicious websites or disrupting internet connectivity. Organizations and individuals using the Avahi-daemon software are strongly advised to apply the forthcoming patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share