cbcvebase.
CVE-2023-29552
published 2023-04-25

CVE-2023-29552: The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use…

PriorityP185high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2023-11-29
Exploited in the wild
EPSS
65.87%
99.2th percentile
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

Affected

4 ranges
VendorProductVersion rangeFixed in
suselinux_enterprise_server
suselinux_enterprise_server
suselinux_enterprise_server
vmwareesxi< 7.07.0

Detection & IOCsextracted from sources · hover to see the quote

port427/UDP
port427/TCP
  • Monitor for unauthenticated SLP service registrations over UDP, which may indicate an attacker staging a reflection amplification attack using spoofed source addresses.
  • Use GreyNoise SLP tag blocklists (updated hourly, compatible with Palo Alto, Cisco, Fortinet, and other next-gen firewalls) to block non-benign sources scanning for internet-exposed SLP endpoints.
  • Prioritize patching or mitigation on VMware ESXi Hypervisor, Konica Minolta printers, Planex Routers, IBM Integrated Management Module (IMM), and SMC IPMI devices, as these are confirmed affected product types with internet-exposed SLP instances.
  • ·The OpenSLP server component (not client) is the affected component; RHEL 8 ships only the client and is NOT affected. RHEL 6, 7, and 9 ship the server component and are affected.
  • ·The vulnerability is inherent to the SLP protocol specification itself and cannot be directly fixed via a code patch; mitigation requires disabling the service or network-level filtering.
  • ·The OpenSLP server is not installed or active by default on standard RHEL deployments; exposure is limited to environments that have explicitly deployed the SLP server.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.