Executive brief
The Service Location Protocol (SLP) allows unauthenticated, remote attackers to register arbitrary services. Attackers can leverage this to conduct reflective denial-of-service (DoS) attacks using spoofed UDP traffic with a significant amplification factor.
Affected products
- Service Location Protocol Project Service Location Protocol (SLP) -
- VMware ESXi up to (excluding) 7.0
- NetApp SMI-S Provider -
- SUSE Manager Server -
- SUSE Linux Enterprise Server 11, 12, 15
Timeline
- 2023-04-25: advisory: CISA and VMware release initial alerts/responses regarding SLP abuse.
- 2023-05-04: other: Initial analysis by NIST.
- 2023-11-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2023-11-08: disclosed