Junglewise Threat Intelligence

CVE-2023-29552: Service Location Protocol (SLP) Denial-of-Service Vulnerability

CVE-2023-29552 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-11-08

Technologies: VMware ESXi, Suse Linux Enterprise Server. Vendors: VMware, Suse, NetApp.

Executive brief

The Service Location Protocol (SLP) allows unauthenticated, remote attackers to register arbitrary services. Attackers can leverage this to conduct reflective denial-of-service (DoS) attacks using spoofed UDP traffic with a significant amplification factor.

Affected products

  • Service Location Protocol Project Service Location Protocol (SLP) -
  • VMware ESXi up to (excluding) 7.0
  • NetApp SMI-S Provider -
  • SUSE Manager Server -
  • SUSE Linux Enterprise Server 11, 12, 15

Timeline

  • 2023-04-25: advisory: CISA and VMware release initial alerts/responses regarding SLP abuse.
  • 2023-05-04: other: Initial analysis by NIST.
  • 2023-11-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-11-08: disclosed