← Vulnerability feed

Vulnerability record · CVE-2023-29552 · published 25 April 2023

CVE-2023-29552: Service Location Protocol unauthenticated service registration enables DoS amplification

NNetapp · Smi S Provider

The Service Location Protocol (SLP, RFC 2608) permits an unauthenticated, remote attacker to register arbitrary services. This allows spoofed UDP traffic to be reflected and amplified, producing a denial-of-service attack against a victim. The flaw affects SLP implementations across multiple vendors and is listed in CISA KEV.

7.5 CVSS 3.1 High CISA KEV since 8 Nov 2023 EPSS 64% · top 0.8%
7.5CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
17References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a high EPSS score and public exploit references, but impact is limited to denial of service with no confidentiality or integrity loss.

What it is

The Service Location Protocol (SLP, RFC 2608) permits an unauthenticated, remote attacker to register arbitrary services. This allows spoofed UDP traffic to be reflected and amplified, producing a denial-of-service attack against a victim. The flaw affects SLP implementations across multiple vendors and is listed in CISA KEV.

Impact

An attacker can direct amplified UDP traffic at a third-party victim, degrading or denying availability of that target. There is no confidentiality or integrity impact; the effect is availability loss.

Attack surface

Reachable remotely over the network via UDP, with no authentication and no user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). The vulnerable service is SLP, commonly on port 427/UDP.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2023-11-08, and EPSS gives a 30-day exploitation probability of 0.65873 (99.2nd percentile). Multiple references are tagged Exploit, indicating public exploitation tooling and techniques exist.

What to do

  • Apply vendor patches or mitigations for SLP on affected products (NetApp, SUSE, VMware, and others listed).
  • Disable the SLP service or block port 427/UDP on all systems reachable from untrusted networks, including Internet-facing hosts.
  • Filter or rate-limit inbound UDP/427 at network boundaries and block outbound spoofed-source UDP where feasible.
  • Inventory hosts running SLP and remove the service where it is not required.
  • Monitor vendor advisories for updated guidance and re-check exposure after changes.

Detection

  • Monitor for anomalous volumes of UDP/427 traffic, especially with spoofed source addresses or directed at external victims.
  • Alert on SLP service registration or directory-agent activity from unexpected or external sources.
  • Baseline normal SLP traffic and flag deviations in packet size, rate, or destination diversity.
  • Review firewall and flow logs for UDP/427 crossing trust boundaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-29552 to the Known Exploited Vulnerabilities catalog on 8 November 2023 as "Service Location Protocol (SLP) Denial-of-Service Vulnerability". Required action: Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet. Federal deadline 29 November 2023.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-reflective-denial-of-service-dos-amplificati Third Party Advisory
https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.htm ExploitThird Party Advisory
https://datatracker.ietf.org/doc/html/rfc2608 Technical Description
https://github.com/curesec/slpload Product
https://security.netapp.com/advisory/ntap-20230426-0001/ Third Party Advisory
https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp ExploitThird Party Advisory
https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks Third Party AdvisoryUS Government Resource
https://www.suse.com/support/kb/doc/?id=000021051 Third Party Advisory
https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-reflective-denial-of-service-dos-amplificati Third Party Advisory
https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.htm ExploitThird Party Advisory
https://datatracker.ietf.org/doc/html/rfc2608 Technical Description
https://github.com/curesec/slpload Product
https://security.netapp.com/advisory/ntap-20230426-0001/ Third Party Advisory
https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp ExploitThird Party Advisory
https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks Third Party AdvisoryUS Government Resource
https://www.suse.com/support/kb/doc/?id=000021051 Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29552 US Government Resource

Track CVE-2023-29552 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-3992VMware ESXi OpenSLP use-after-free allows remote code executionOpenSLP as used in VMware ESXi contains a use-after-free flaw reachable over port 427 on the management network. An unauthenticated attacker with net…KEVEPSS 83%analysed9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2023-29552), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.