The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
2023-04-25T16:15:09.537
2025-03-27T14:08:54.180
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netapp | smi-s_provider | - | Yes |
Application | suse | manager_server | - | Yes |
Operating System | suse | linux_enterprise_server | 11 | Yes |
Operating System | suse | linux_enterprise_server | 12 | Yes |
Operating System | suse | linux_enterprise_server | 12 | Yes |
Operating System | suse | linux_enterprise_server | 15 | Yes |
Operating System | suse | linux_enterprise_server | 15 | Yes |
Operating System | vmware | esxi | < 7.0 | Yes |
Application | service_location_protocol_project | service_location_protocol | - | Yes |