ZeroHour

CVE-2023-29552

KEV PoC ×2mass

SLP DoS Amplification Flaw Affects VMware ESXi, SUSE Linux, NetApp

CISA: Service Location Protocol (SLP) Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
66%p99
Published
()
KEV added
AI analysis

CVE-2023-29552 is a protocol-level flaw in the IETF Service Location Protocol (SLP, RFC 2608) that permits an unauthenticated, remote attacker to register arbitrary services using spoofed UDP traffic sent to port 427. Any system running an SLP agent reachable on UDP 427 on an untrusted network can be abused as a reflector/amplifier, with reported amplification factors as high as roughly 2,200x, enabling large denial-of-service floods against third-party victims. The impact is availability only (CVSS 3.1: 7.5, A:H), and the attacker needs no privileges or user interaction. Affected parties include organizations running VMware ESXi, SUSE Linux Enterprise Server, or NetApp products (SMI-S Provider, Manager Server), as well as any host running the open-source Service Location Protocol implementation, since SLP is commonly enabled by default. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-11-08 and is under active exploitation, with a high EPSS of 65.9% (99th percentile).

What to do: Per the CISA required action, disable the SLP service (slpd) where it is not needed, or restrict UDP port 427 to trusted management networks and never expose it to the internet. Apply the mitigations or patches issued in the VMware, SUSE, and NetApp advisories, and inventory all hosts listening on 427/UDP, prioritizing internet-facing and untrusted-network systems since the flaw is under active exploitation.

Affected
Service Location Protocol project / IETF Service Location Protocol (SLP, RFC 2608)All implementations/versions; protocol-level flaw, no fixed version specified in source data
VMware ESXi
SUSE Linux Enterprise Server
NetApp SMI-S Provider
NetApp Manager Server
Estimated exposure
masshundreds of thousands of servers or more plausibly run SLP enabled by default (exact count, and the number exposing UDP 427 to the internet, unknown) — SLP is enabled by default on very widely deployed platforms such as VMware ESXi and SUSE Linux Enterprise Server, whose combined installed base is plausibly in the hundreds of thousands to millions of hosts, though public-scan counts of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

CISA Known Exploited Vulnerability
Affected
IETF Service Location Protocol (SLP)
Required action
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
Due date
Ransomware use
Unknown
Vendors
netappsusevmwareservice location protocol project
Products
smi-s provider, manager server, linux enterprise server, esxi, service location protocol
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news