CVE-2023-29552: Service Location Protocol (SLP) Denial-of-Service Vulnerability
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Other sources
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the SLP service on all systems running on untrusted networks, including those directly connected to the Internet.
Service Location Protocol (SLP) service_enabled = false - Compensating control
Block or close UDP port 427 on all systems on untrusted networks (for example via firewall/ACL/WAF/network controls), including systems directly connected to the Internet.
Event History
Frequently Asked Questions
What is CVE-2023-29552?
CVE-2023-29552 is a vulnerability in the Service Location Protocol (SLP) that allows an unauthenticated remote attacker to register arbitrary services and conduct a denial-of-service attack with a significant amplification factor.
What is the severity of CVE-2023-29552?
CVE-2023-29552 has a severity value of 7.5, which is classified as high.
Which software products are affected by CVE-2023-29552?
The following software products are affected by CVE-2023-29552: Netapp Smi-s Provider, SUSE Manager Server, SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 12 with SAP, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 with SAP, VMware ESXi, and Service Location Protocol Project Service Location Protocol.
How can an unauthenticated remote attacker exploit CVE-2023-29552?
An unauthenticated remote attacker can exploit CVE-2023-29552 by sending spoofed UDP traffic to register arbitrary services, causing a denial-of-service attack with a significant amplification factor.
Where can I find more information about CVE-2023-29552?
You can find more information about CVE-2023-29552 at the following references: [link1], [link2], [link3].