Back

HIGH KEV

openslp: Reflective denial of service amplification attack via UDP

Published Apr 25, 2023 ·Due Nov 29, 2023

Description

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

Affected products

Remediation

Red Hat statement

The OpenSLP protocol specification makes it prone to UDP amplification attacks, and the abuse of exposed OpenSLP servers can be used to contribute to Distributed Denial of Service attacks. Due to the protocol implementation, this issue can't be directly fixed. This issue affects the Server component of the openslp package, which is only shipped on Red Hat Enterprise Linux 7 and 9. RHEL 8 only ships the Client component, that is not affected by this CVE. The OpenSLP server is not installed and active on any standard RHEL deployments. If you are using the OpenSLP server, Red Hat recommends to do so in a secure and controlled network environment.

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 25, 2023
Updated Oct 21, 2025
Reserved Apr 7, 2023
CISA Vulnrichment
Updated Jan 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 25, 2023
ENISA EUVD
Assigner mitre
Published Apr 25, 2023
Updated Oct 21, 2025
Exploited since Nov 8, 2023
EUVD-2023-33094