CVE-2023-29552
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Service Location Protocol (SLP) Denial-of-Service Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
תיאור (מקור, אנגלית)
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 66% (אחוזון 100) נכון ל-25/7/2026
מוצרים מושפעים
netapp: smi-s provider; suse: manager server; suse: linux enterprise server; vmware: esxi; service_location_protocol_project: service location protocol
קישורים
- https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Deni… ExploitThird Party Advisory
- https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-d… ExploitThird Party Advisory
- https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Deni… ExploitThird Party Advisory
- https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-d… ExploitThird Party Advisory
- https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-re… Third Party Advisory
- https://datatracker.ietf.org/doc/html/rfc2608 Technical Description
- https://github.com/curesec/slpload Product
- https://security.netapp.com/advisory/ntap-20230426-0001/ Third Party Advisory
- https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-prot… Third Party AdvisoryUS Government Resource
- https://www.suse.com/support/kb/doc/?id=000021051 Third Party Advisory