Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29552


The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.


Published

2023-04-25T16:15:09.537

Last Modified

2025-03-27T14:08:54.180

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netapp smi-s_provider - Yes
Application suse manager_server - Yes
Operating System suse linux_enterprise_server 11 Yes
Operating System suse linux_enterprise_server 12 Yes
Operating System suse linux_enterprise_server 12 Yes
Operating System suse linux_enterprise_server 15 Yes
Operating System suse linux_enterprise_server 15 Yes
Operating System vmware esxi < 7.0 Yes
Application service_location_protocol_project service_location_protocol - Yes

References