{"id":"CVE-2023-29552","vendor_project":"IETF","product":"Service Location Protocol (SLP)","vulnerability_name":"Service Location Protocol (SLP) Denial-of-Service Vulnerability","date_added":"2023-11-08","due_date":"2023-11-29","known_ransomware_use":"Unknown","short_description":"The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.","required_action":"Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","nvd_published":"2023-04-25","nvd_status":"Analyzed","epss":0.65873,"epss_percentile":0.99238,"cvss_score":7.5,"days_published_to_kev":197,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2023-29552","by":"CyberMax"}