Vulnerability record · CVE-2010-2156 · published 7 June 2010
CVE-2010-2156: ISC DHCP server exits on zero-length client ID
Isc · Dhcp
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 terminate when they receive a DHCP packet carrying a zero-length client ID. Because the DHCP server process exits, the flaw can take down address assignment for the whole network segment it serves.
Description
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityUnauthenticated remote crash of a core network service with a public exploit and very high EPSS, though impact is limited to availability.
What it is
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 terminate when they receive a DHCP packet carrying a zero-length client ID. Because the DHCP server process exits, the flaw can take down address assignment for the whole network segment it serves.
Impact
An unauthenticated attacker can crash the DHCP daemon, causing a denial of service for all clients relying on that server for leases.
Attack surface
Reachable over the network via a crafted DHCP request; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.76412 (99.5th percentile) and a public Exploit-DB entry (14185) exists, so exploitation is practical and likely.
What to do
- Upgrade to ISC DHCP 4.1.1-P1 or 4.0.2-P1 (or later) as listed in the vendor release notes.
- Apply the distribution vendor update (e.g., Fedora, Mandriva advisories) if using a packaged build.
- Restrict DHCP traffic to trusted network segments and block UDP 67/68 from untrusted sources at the perimeter.
- Run the DHCP service under a supervisor that restarts it automatically, and monitor for unexpected exits.
Detection
- Alert on unexpected dhcpd process termination or restart events in system and service logs.
- Monitor for DHCP packets containing a zero-length client identifier on the wire.
- Track DHCP service availability gaps and lease assignment failures as a DoS indicator.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2156 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2156), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.