CVE-2023-29552
Service Location Protocol (SLP) Denial-of-Service Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 November 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 65.87% probability · 99th percentile
- CISA KEV
- Listed 8 November 2023 · due 29 November 2023
- Affected
- netapp/smi-s provider · suse/manager server · suse/linux enterprise server · vmware/esxi · service location protocol project/service location protocol
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks.; https://nvd.nist.gov/vuln/detail/CVE-2023-29552
References
- https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-reflective-denial-of-service-dos-amplification-vulnerability-in-slp.htmlThird Party Advisory
- https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.htmlExploit, Third Party Advisory
- https://datatracker.ietf.org/doc/html/rfc2608Technical Description
- https://github.com/curesec/slploadProduct
- https://security.netapp.com/advisory/ntap-20230426-0001/Third Party Advisory
- https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slpExploit, Third Party Advisory
- https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacksThird Party Advisory, US Government Resource
- https://www.suse.com/support/kb/doc/?id=000021051Third Party Advisory
- https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-reflective-denial-of-service-dos-amplification-vulnerability-in-slp.htmlThird Party Advisory
- https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.htmlExploit, Third Party Advisory
- https://datatracker.ietf.org/doc/html/rfc2608Technical Description
- https://github.com/curesec/slploadProduct
- https://security.netapp.com/advisory/ntap-20230426-0001/Third Party Advisory
- https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slpExploit, Third Party Advisory
- https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacksThird Party Advisory, US Government Resource
- https://www.suse.com/support/kb/doc/?id=000021051Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29552US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.