← Vulnerability feed

Vulnerability record · CVE-2010-2156 · published 7 June 2010

CVE-2010-2156: ISC DHCP server exits on zero-length client ID

Isc · Dhcp

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 terminate when they receive a DHCP packet carrying a zero-length client ID. Because the DHCP server process exits, the flaw can take down address assignment for the whole network segment it serves.

5.0 CVSS 2.0 Medium EPSS 76% · top 0.5% CWE-189 · CWE-189
5.0CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote crash of a core network service with a public exploit and very high EPSS, though impact is limited to availability.

What it is

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 terminate when they receive a DHCP packet carrying a zero-length client ID. Because the DHCP server process exits, the flaw can take down address assignment for the whole network segment it serves.

Impact

An unauthenticated attacker can crash the DHCP daemon, causing a denial of service for all clients relying on that server for leases.

Attack surface

Reachable over the network via a crafted DHCP request; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.76412 (99.5th percentile) and a public Exploit-DB entry (14185) exists, so exploitation is practical and likely.

What to do

  • Upgrade to ISC DHCP 4.1.1-P1 or 4.0.2-P1 (or later) as listed in the vendor release notes.
  • Apply the distribution vendor update (e.g., Fedora, Mandriva advisories) if using a packaged build.
  • Restrict DHCP traffic to trusted network segments and block UDP 67/68 from untrusted sources at the perimeter.
  • Run the DHCP service under a supervisor that restarts it automatically, and monitor for unexpected exits.

Detection

  • Alert on unexpected dhcpd process termination or restart events in system and service logs.
  • Monitor for DHCP packets containing a zero-length client identifier on the wire.
  • Track DHCP service availability gaps and lease assignment failures as a DoS indicator.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0692Isc dhcp memory buffer overflow vulnerabilityStack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 b…EPSS 26%7.8CVE-2011-2748Isc dhcp improper input validation vulnerabilityThe server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…EPSS 39%7.8CVE-2011-2749Isc dhcp improper input validation vulnerabilityThe server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…EPSS 39%7.8CVE-2011-0413Isc dhcp improper input validation vulnerabilityThe DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attacker…EPSS 33%7.5CVE-2018-5732Isc dhcp memory buffer overflow vulnerabilityFailure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause…EPSS 5.2%7.5CVE-2017-3144ISC DHCP OMAPI connection cleanup failure exhausts socket descriptorsISC DHCP fails to properly clean up closed OMAPI connections, so socket descriptors are not released back to the server's pool. Repeated connections …EPSS 73%analysed7.5CVE-2018-5733Isc dhcp integer overflow vulnerabilityA malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit ref…EPSS 20%7.5CVE-2011-0997ISC DHCP dhclient command injection via DHCP hostnamedhclient in ISC DHCP 3.0.x through 4.2.x (before 4.2.1-P1), 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 fails to validate the hostname o…EPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2010-2156), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.