CVE-2023-29552
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Published:Apr 25, 2023
Last Modified:Oct 31, 2025
EPS:Apr 25, 2023
EPSS Score:0.9264
CVSS Score:7.5
CISA Notification
Description
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Required Action:
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
Notes:
No extra notes provided.
Due Date
Nov 29, 2023
1017 days ago
Alert Date
Nov 8, 2023
1038 days ago
Affected Products
Vendor
Product
Action
Vendor
Netapp
Product
Smi-s Provider
Netapp
Smi-s Provider
Vendor
Service Location Protocol Project
Product
Service Location Protocol
Service Location Protocol Project
Service Location Protocol
Vendor
Suse
Product
Linux Enterprise Server
Suse
Linux Enterprise Server
Vendor
Suse
Product
Manager Server
Suse
Manager Server
Vendor
Vmware
Product
Esxi
Vmware
Esxi
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
