The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNetapp Smi S Provider
APPNetappall versionsService Location Protocol Project Service Location Protocol
APPService Location Protocol Projectall versionsSUSE Linux Enterprise Server
OSSuse111215SUSE Manager Server
APPSuseall versionsVMware ESXi
OSVmware< 7.0
CISA KEV — detailsi
- Vendori
- IETF
- Producti
- Service Location Protocol (SLP)
- Added to KEVi
- November 8, 2023
- Remediation deadline (US Federal)i
- November 29, 2023(overdue)
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.
Related vulnerabilities
VMware ESXi/Workstation: TOCTOU umożliwia ucieczkę z VM przez VMX process
VMware ESXi OpenSLP — use-after-free umożliwiający RCE (CVE-2020-3992)
Krytyczny heap overwrite w OpenSLP dla VMware ESXi i Horizon DaaS
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries