CVE-2023-29552
Service Location Protocol (SLP) Denial-of-Service Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.5
- EPSS
- 65.9% 백분위 99.2% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.11.29
- 공개일
- 2023.04.26
CISA KEV에 등록된 실제 악용 확인 취약점
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
공급사 IETF
제품 Service Location Protocol (SLP)
영향 버전 n/a, 11, 12, 15, < 7.0
수정 버전 7.0
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
조치 기한: 2023.11.29CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE 미등록
KEV 등록일 2023.11.08
랜섬웨어 캠페인 사용 미확인
CISA 비고 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks.; https://nvd.nist.gov/vuln/detail/CVE-2023-29552
EPSS 데이터 기준일 2026.06.27