QID 216312

Date Published: 2023-05-03

QID 216312: VMware ESXi 6.7 Reflective Denial of Service (DoS) Amplification Vulnerability in SLP

VMware ESXi is an enterprise level computer virtualization product.

Affected Version:
VMware ESXi 6.7.x

QID Detection Logic (authenticated):
This QID checks for slp service using command "chkconfig --list | grep slpd"

Successful exploitation of this vulnerability could lead to Denial of Service (DoS) attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to upgrade to a supported release ESXi 7.0 U2c and ESXi 8.0 GA and newer, for more details refer Reflective Denial-of-Service (DoS) in SLP

    CVEs related to QID 216312

    Software Advisories
    Advisory ID Software Component Link