SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-29552

Service Location Protocol (SLP) Denial-of-Service Vulnerability

KEVHIGH 7.5EPSS 65.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 November 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
65.87% probability · 99th percentile
CISA KEV
Listed 8 November 2023 · due 29 November 2023
Affected
netapp/smi-s provider · suse/manager server · suse/linux enterprise server · vmware/esxi · service location protocol project/service location protocol
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks.; https://nvd.nist.gov/vuln/detail/CVE-2023-29552

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.