Hello,
Has anyone else seen an mDNS Vulnerability when doing an unauthenticated scan against any of the media players?
This was scanned using Nessus Pro.
I understand the box itself is a flavour of Linux but has no terminal access.
I have tried the NetBIOS settings on BrightAuthor client but doesnt change anything on the device.
Any help is appreciated.
Info on mDNS: The remote service understands the Bonjour (also known as ZeroConf or mDNS) protocol, which allows anyone to uncover information from the remote host such as its operating system type.
Impact
|
An mDNS response to a unicast query originating outside of the local link network may result in information disclosure, such as disclosing the device type/model that responds to the request or the operating system running such software. The mDNS response may also be used to amplify denial of service attacks against other networks. |
Solution
|
Block inbound and outbound mDNS on the WAN If such mDNS behavior is not a requirement for your organization, consider blocking the mDNS UDP port 5353 from entering or leaving your local link network. |
|
Disable mDNS services Some software and devices may allow disabling of the mDNS services. Please consult with the vendor of your product. |
