EXPOSURES › CVE-2023-29552
CVE-2023-29552
HIGH ⌖ ON CISA KEV · EXPLOITEDIETF SLP DoS vulnerability allows remote attackers to conduct a significant DoS attack.
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor. This vulnerability is actively exploited and poses a significant risk to systems using SLP.
Shame score — The vulnerability is actively exploited and allows for a significant amplification factor in a DoS attack, making it a high-risk issue.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.