Skip to main content

CVE-2023-29552

7.5
HIGHCVSS v3.1 Base Score
92.14%
HIGH RiskEPSS (100th percentile)
KEV
NVD-CWE-noinfo

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

Published: 4/25/2023
Modified: 10/31/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Service Location Protocol (SLP) Denial-of-Service Vulnerability

Vendor / Product:

IETF Service Location Protocol (SLP)

Required Action:

Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.

Due Date: 11/29/2023(OVERDUE)
Added to KEV:

11/8/2023

Notes:

This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks.; https://nvd.nist.gov/vuln/detail/CVE-2023-29552

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Score (Exploitation Probability)

92.14%HIGH Exploitation Risk
100th percentile

This vulnerability has a 92.14% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities