New SLP Reflection Vector Gives Attackers a 2,200x Amplifier
Researchers at Bitsight and Curesec have disclosed a new DDoS reflection and amplification vector that abuses the legacy Service Location Protocol (SLP). Tracked as CVE-2023-29552, the technique has an amplification factor of up to 2,200x, placing it among the largest such factors observed to date. Cloudflare says its automated DDoS protection already mitigates this attack class for its customers.
The Protocol Behind the Attack
SLP is a service discovery protocol introduced by Sun Microsystems in 1997. It was designed so devices on a local network could discover one another without prior configuration. Over time, it has been largely displaced by alternatives such as UPnP, mDNS/Zeroconf, and WS-Discovery, but it remains enabled in a range of commercial products.
SLP lacks any authentication mechanism and was never intended for exposure to the public Internet. Despite that, the research teams found roughly 35,000 Internet-facing endpoints that leave SLP accessible to anyone. The UDP variant of the protocol, once reachable, can be used to reflect and amplify traffic by a factor up to 2,200x — the third highest amplification factor ever documented.
Mitigation Advice for Network Operators
Organizations running SLP-enabled devices should treat any public exposure as a risk. The researchers recommend blocking UDP port 427 using access control lists or similar measures, since this port carries little legitimate traffic on the open Internet and can be filtered without meaningful collateral impact. Cloudflare Magic Transit customers can implement such rules via Magic Firewall.
With details of the vulnerability now public, Cloudflare anticipates that SLP-based DDoS attacks will become more frequent as attackers begin building tooling around the newly disclosed vector.



