CVE Vulnerabilities

CVE-2023-29552

Published: Apr 25, 2023 | Modified: Oct 31, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

Affected Software

NameVendorStart VersionEnd Version
Smi-s_providerNetapp- (including)- (including)
Openslp-dfsgUbuntuesm-infra-legacy/trusty*
Openslp-dfsgUbuntuesm-infra/xenial*
Openslp-dfsgUbuntutrusty*
Openslp-dfsgUbuntutrusty/esm*
Openslp-dfsgUbuntuxenial*

References