Aller au contenu

Fiche vulnérabilité

CVE-2023-29552 : faille exploitée netapp smi-s provider (CVSS 7.5)

Description

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
25 avr. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • netapp smi-s provider
  • suse manager server
  • suse linux enterprise server
  • vmware esxi
  • service location protocol project service location protocol

Correctif et mesures

Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.

Références

Rechercher une autre vulnérabilité dans la base CVE