CVE-2023-29552: Service Location Protocol (SLP) Denial-of-Service Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2023-11-08. EPSS: 64% chance of exploitation in the next 30 days.
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Affected products
- Netapp Smi-S Provider: affected versions not specified
- Service Location Protocol Project Service Location Protocol: affected versions not specified
- Suse Linux Enterprise Server: version 11 only; version 12 only; version 15 only
- Suse Manager Server: affected versions not specified
- VMware ESXi: before 7.0 (fixed in 7.0)
Published 2023-04-25. Last modified 2026-06-17.