netVigilance Vulnerability intelligence since 2004
CVE-2023-29552 · netVigilance record NV23-0161

Service Location Protocol (SLP) Denial-of-Service

past due

What to do

Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.

CISA deadline 2023-11-29 · passed 2 years 9 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA

What happened

The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.

Who is affected

IETF Service Location Protocol (SLP). Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.

Timeline

  1. Added to CISA KEVExploitation in the wild confirmed by CISA
  2. CISA remediation deadlinepassed 2 years 9 months ago

Sources