CVE-2023-29552
published 2023-04-25CVE-2023-29552: The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use…
PriorityP185high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2023-11-29
Exploited in the wild
EPSS
65.87%
99.2th percentile
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| vmware | esxi | < 7.0 | 7.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated SLP service registrations over UDP, which may indicate an attacker staging a reflection amplification attack using spoofed source addresses. ↗
- →Use GreyNoise SLP tag blocklists (updated hourly, compatible with Palo Alto, Cisco, Fortinet, and other next-gen firewalls) to block non-benign sources scanning for internet-exposed SLP endpoints. ↗
- →Prioritize patching or mitigation on VMware ESXi Hypervisor, Konica Minolta printers, Planex Routers, IBM Integrated Management Module (IMM), and SMC IPMI devices, as these are confirmed affected product types with internet-exposed SLP instances. ↗
- ·The OpenSLP server component (not client) is the affected component; RHEL 8 ships only the client and is NOT affected. RHEL 6, 7, and 9 ship the server component and are affected. ↗
- ·The vulnerability is inherent to the SLP protocol specification itself and cannot be directly fixed via a code patch; mitigation requires disabling the service or network-level filtering. ↗
- ·The OpenSLP server is not installed or active by default on standard RHEL deployments; exposure is limited to environments that have explicitly deployed the SLP server. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-288r-5qm5-qp55: The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services
ghsa_unreviewed·2023-04-25
CVE-2023-29552 [HIGH] GHSA-288r-5qm5-qp55: The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
OSV
CVE-2023-29552: The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services
osv·2023-04-24·CVSS 7.5
CVE-2023-29552 [HIGH] CVE-2023-29552: The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
VulnCheck
Service Location Protocol (SLP) Denial-of-Service Vulnerability
vulncheck·2023·CVSS 7.5
CVE-2023-29552 [HIGH] Service Location Protocol (SLP) Denial-of-Service Vulnerability
Service Location Protocol (SLP) Denial-of-Service Vulnerability
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.
Affected: IETF Service Location Protocol (SLP)
Required Action: Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
Known Ransomware Campaign Use: Known
Exploitation References: https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.html; https://www.cisa.gov/sites/defa
CISA
Service Location Protocol (SLP) Denial-of-Service Vulnerability
cisa·2023-11-08·CVSS 7.5
CVE-2023-29552 [HIGH] Service Location Protocol (SLP) Denial-of-Service Vulnerability
Vulnerability: Service Location Protocol (SLP) Denial-of-Service Vulnerability
Affected: IETF Service Location Protocol (SLP)
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.
Required Action: Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status.
Red Hat
openslp: Reflective denial of service amplification attack via UDP
vendor_redhat·2023-04-25·CVSS 7.5
CVE-2023-29552 [HIGH] CWE-406 openslp: Reflective denial of service amplification attack via UDP
openslp: Reflective denial of service amplification attack via UDP
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
.The Service Location Protocol (SLP) is vulnerable to an attack through UDP
The OpenSLP provides a dynamic configuration mechanism for applications in local area networks, such as printers and file servers. However, SLP is vulnerable to a reflective denial of service amplification attack through UDP on systems connected to the internet. SLP allows an unauthenticated attacker to register new services without limits set by the SLP implementation. By using UDP and spoofing
No detection rules found.
No public exploits indexed.
Checkpoint
1st May – Threat Intelligence Report
blogs_checkpoint·2023-05-01·CVSS 9.8
CVE-2023-27350 [CRITICAL] 1st May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st May, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
A threat actor was able to generate some mail keys of American Telecom giant AT&T, and used it to take control of AT&T customers’ email addresses. Victims report that cryptocurrency accounts connected to their AT&T emails were drained, suggesting a financial motivation for the attackers.
Microsoft warns of a recent wave in exploitat
Greynoiseio
SLP Sliding Away With Reflection Amplification Thanks To CVE-2023-29552
blogs_greynoiseio·CVSS 7.5
[HIGH] SLP Sliding Away With Reflection Amplification Thanks To CVE-2023-29552
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-reflective-denial-of-service-dos-amplification-vulnerability-in-slp.htmlhttps://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.htmlhttps://datatracker.ietf.org/doc/html/rfc2608https://github.com/curesec/slploadhttps://security.netapp.com/advisory/ntap-20230426-0001/https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slphttps://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attackshttps://www.suse.com/support/kb/doc/?id=000021051https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-reflective-denial-of-service-dos-amplification-vulnerability-in-slp.htmlhttps://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.htmlhttps://datatracker.ietf.org/doc/html/rfc2608https://github.com/curesec/slploadhttps://security.netapp.com/advisory/ntap-20230426-0001/https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slphttps://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attackshttps://www.suse.com/support/kb/doc/?id=000021051https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29552
2023-04-25
Published
2023-11-08
Added to CISA KEV
Exploited in the wild