openslp: Reflective denial of service amplification attack via UDP
Published Apr 25, 2023 ·Due Nov 29, 2023
7.5
HIGHCVSS 3.1
EPSS 63.98%
Description
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
Affected products
No data.
Configuration 1
- n/a
Configuration 2
- n/a
- 11
- 12
- 12
- 15
- 15
Configuration 4
- n/a
No data.
Red Hat Enterprise Linux 6
openslp
Out of support scope
Red Hat Enterprise Linux 7
openslp
Will not fix
Red Hat Enterprise Linux 8
openslp
Not affected
Red Hat Enterprise Linux 9
openslp
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openslp | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openslp | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | openslp | Not affected | n/a |
| Red Hat Enterprise Linux 9 | openslp | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The OpenSLP protocol specification makes it prone to UDP amplification attacks, and the abuse of exposed OpenSLP servers can be used to contribute to Distributed Denial of Service attacks. Due to the protocol implementation, this issue can't be directly fixed. This issue affects the Server component of the openslp package, which is only shipped on Red Hat Enterprise Linux 7 and 9. RHEL 8 only ships the Client component, that is not affected by this CVE. The OpenSLP server is not installed and active on any standard RHEL deployments. If you are using the OpenSLP server, Red Hat recommends to do so in a secure and controlled network environment.
References (15)
- https://access.redhat.com/security/cve/CVE-2023-29552 Vendor Advisory
- https://blogs.vmware.com/security/2023/04/vmware-response-to-cve-2023-29552-reflective-denial-of-service-dos-amplification-vulnerability-in-slp.html Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2183534 Issue Tracking
- https://curesec.com/blog/article/CVE-2023-29552-Service-Location-Protocol-Denial-of-Service-Amplification-Attack-212.html ExploitThird Party Advisory
- https://datatracker.ietf.org/doc/html/rfc2608 Technical Description
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-33094 Advisory
- https://github.com/curesec/slpload Product
- https://nvd.nist.gov/vuln/detail/CVE-2023-29552
- https://security.netapp.com/advisory/ntap-20230426-0001/ Third Party Advisory
- https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29552 government-resourceUS Government Resource
- https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks Third Party AdvisoryUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2023-29552
- https://www.suse.com/support/kb/doc/?id=000021051 Third Party Advisory
Change history (0)
No recorded changes yet.