CVE-2023-29552
KEV PoC ×2massSLP DoS Amplification Flaw Affects VMware ESXi, SUSE Linux, NetApp
CISA: Service Location Protocol (SLP) Denial-of-Service Vulnerability
CVE-2023-29552 is a protocol-level flaw in the IETF Service Location Protocol (SLP, RFC 2608) that permits an unauthenticated, remote attacker to register arbitrary services using spoofed UDP traffic sent to port 427. Any system running an SLP agent reachable on UDP 427 on an untrusted network can be abused as a reflector/amplifier, with reported amplification factors as high as roughly 2,200x, enabling large denial-of-service floods against third-party victims. The impact is availability only (CVSS 3.1: 7.5, A:H), and the attacker needs no privileges or user interaction. Affected parties include organizations running VMware ESXi, SUSE Linux Enterprise Server, or NetApp products (SMI-S Provider, Manager Server), as well as any host running the open-source Service Location Protocol implementation, since SLP is commonly enabled by default. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-11-08 and is under active exploitation, with a high EPSS of 65.9% (99th percentile).
What to do: Per the CISA required action, disable the SLP service (slpd) where it is not needed, or restrict UDP port 427 to trusted management networks and never expose it to the internet. Apply the mitigations or patches issued in the VMware, SUSE, and NetApp advisories, and inventory all hosts listening on 427/UDP, prioritizing internet-facing and untrusted-network systems since the flaw is under active exploitation.
| Service Location Protocol project / IETF Service Location Protocol (SLP, RFC 2608) | All implementations/versions; protocol-level flaw, no fixed version specified in source data |
| VMware ESXi | — |
| SUSE Linux Enterprise Server | — |
| NetApp SMI-S Provider | — |
| NetApp Manager Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
- Affected
- IETF Service Location Protocol (SLP)
- Required action
- Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
- Due date
- Ransomware use
- Unknown
- Vendors
- netappsusevmwareservice location protocol project
- Products
- smi-s provider, manager server, linux enterprise server, esxi, service location protocol
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H