• News/
  • https://www.bleepingcomputer.com/news/security/new-loop-dos-attack-may-impact-up-to-300-000-online-systems/

New ‘Loop DoS’ attack may impact up to 300,000 online systems

BleepingComputer
·
Bill Toulas
·
Published Mar 20, 2024
·
Updated

A new denial-of-service attack dubbed 'Loop DoS' targeting application layer protocols can pair network services into an indefinite communication loop that creates large volumes of traffic. Devised by researchers at the CISPA Helmholtz-Center for Information Security, the attack uses the User Datagram Protocol (UDP) and impacts an estimated 300,000 host and their networks. The attack is possible due to a vulnerability, currently tracked as CVE-2024-2169, in the implementation of the UDP protocol, which is susceptible to IP spoofing and does not provide sufficient packet verification. An attacker exploiting the vulnerability creates a self-perpetuating mechanism that generates excessive traffic without limits and without a way to stop it, leading to a denial-of-service (DoS) condition on the target system or even an entire network. Loop DoS relies on IP spoofing and can be triggered from a single host that sends one message to start the communication. According to the Carnegie Mellon CERT Coordination Center (CERT/CC) there are three potential outcomes when an attacker leverages the vulnerability: CISPA researchers Yepeng Pan and Professor Dr. Christian Rossow say the potential impact is notable, spanning both outdated (QOTD, Chargen, Echo) and modern protocols (DNS, NTP, TFTP) that are crucial for basic internet-based functions like time synchronization, domain name resolution, and file transfer without authentication. "If two application servers have a vulnerable implementa...

Read full article

Affected Software

5 affected components
Broadcom UDP
Cisco UDP
Honeywell UDP
Microsoft UDP
Mikrotik UDP
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new denial-of-service attack called 'Loop DoS' that can affect up to 300,000 online systems.

2

What security implications are discussed regarding the Loop DoS attack?

The Loop DoS attack can create large volumes of traffic by causing network services to enter an indefinite communication loop.

3

What types of systems are impacted by this new attack?

The Loop DoS attack primarily targets application layer protocols and can impact various online systems.

4

Which vendors' products are affected by the Loop DoS attack?

Affected products include UDP services from vendors such as Broadcom, Cisco, Honeywell, Microsoft, and MikroTik.

5

What measures can be taken to mitigate the Loop DoS attack?

The article suggests that organizations should review their network configurations and apply appropriate updates to the affected UDP services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203