← לוח פגיעויות

CVE-2023-29552

גבוהה 7.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Service Location Protocol (SLP) Denial-of-Service Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.

תיאור (מקור, אנגלית)

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
66% (אחוזון 100) נכון ל-25/7/2026

מוצרים מושפעים

netapp: smi-s provider; suse: manager server; suse: linux enterprise server; vmware: esxi; service_location_protocol_project: service location protocol

קישורים