Service Location Protocol(SLP, RFC 2608)은 인증되지 않은 원격 공격자가 임의의 서비스를 등록할 수 있도록 합니다. 이로 인해 공격자가 스푸핑된 UDP 트래픽을 사용하여 상당한 증폭 계수로 서비스 거부 공격을 수행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
영향 제품·버전
제품 IETF Service Location Protocol (SLP)
영향 버전 IETF Service Location Protocol (SLP) 11, 12, 15, < 7.0
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
조치 기한: 2023.11.29
해당사항 확인방법
IETF Service Location Protocol (SLP)의 현재 전체 버전이 공식 영향 범위(IETF Service Location Protocol (SLP) 11, 12, 15, < 7.0)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 IETF Service Location Protocol (SLP) 7.0 기준을 충족하는지 확인합니다. 이어서 서비스 거부(DoS) 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.
필드별 과거 원문을 추정하지 않습니다. 각 시점의 현재 값과 공식 출처를 대조해 변경 여부를 확인하세요.
기술 정보
CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE 미등록
KEV 등록일 2023.11.08
랜섬웨어 캠페인 사용 미확인
CISA 비고 This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on the patching status. For more information please see https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp and https://www.cisa.gov/news-events/alerts/2023/04/25/abuse-service-location-protocol-may-lead-dos-attacks.; https://nvd.nist.gov/vuln/detail/CVE-2023-29552