The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.
| Software | From | Fixed in |
|---|---|---|
| suse / linux_enterprise_server | 11 | 11.x |
| suse / linux_enterprise_server | 12 | 12.x |
| suse / linux_enterprise_server | 15 | 15.x |
| vmware / esxi | - | 7.0 |