Vulnerability record · CVE-2023-29552 · published 25 April 2023
CVE-2023-29552: Service Location Protocol unauthenticated service registration enables DoS amplification
NNetapp · Smi S Provider
The Service Location Protocol (SLP, RFC 2608) permits an unauthenticated, remote attacker to register arbitrary services. This allows spoofed UDP traffic to be reflected and amplified, producing a denial-of-service attack against a victim. The flaw affects SLP implementations across multiple vendors and is listed in CISA KEV.
Description
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityIt is in CISA KEV with a high EPSS score and public exploit references, but impact is limited to denial of service with no confidentiality or integrity loss.
What it is
The Service Location Protocol (SLP, RFC 2608) permits an unauthenticated, remote attacker to register arbitrary services. This allows spoofed UDP traffic to be reflected and amplified, producing a denial-of-service attack against a victim. The flaw affects SLP implementations across multiple vendors and is listed in CISA KEV.
Impact
An attacker can direct amplified UDP traffic at a third-party victim, degrading or denying availability of that target. There is no confidentiality or integrity impact; the effect is availability loss.
Attack surface
Reachable remotely over the network via UDP, with no authentication and no user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). The vulnerable service is SLP, commonly on port 427/UDP.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-11-08, and EPSS gives a 30-day exploitation probability of 0.65873 (99.2nd percentile). Multiple references are tagged Exploit, indicating public exploitation tooling and techniques exist.
What to do
- Apply vendor patches or mitigations for SLP on affected products (NetApp, SUSE, VMware, and others listed).
- Disable the SLP service or block port 427/UDP on all systems reachable from untrusted networks, including Internet-facing hosts.
- Filter or rate-limit inbound UDP/427 at network boundaries and block outbound spoofed-source UDP where feasible.
- Inventory hosts running SLP and remove the service where it is not required.
- Monitor vendor advisories for updated guidance and re-check exposure after changes.
Detection
- Monitor for anomalous volumes of UDP/427 traffic, especially with spoofed source addresses or directed at external victims.
- Alert on SLP service registration or directory-agent activity from unexpected or external sources.
- Baseline normal SLP traffic and flag deviations in packet size, rate, or destination diversity.
- Review firewall and flow logs for UDP/427 crossing trust boundaries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-29552 to the Known Exploited Vulnerabilities catalog on 8 November 2023 as "Service Location Protocol (SLP) Denial-of-Service Vulnerability". Required action: Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet. Federal deadline 29 November 2023.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-29552 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.