Vulnerability record · CVE-2015-8605 · published 14 January 2016
CVE-2015-8605: ISC DHCP invalid UDP length field causes denial of service
Sophos · Unified Threat Management Up2date
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 fails to properly validate the length field in a UDP IPv4 packet, allowing a remote attacker to crash the DHCP service. Because DHCP is a core network service, a crash can disrupt address assignment for clients on the affected segment.
Description
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityCVSS rates this medium (6.5) with availability-only impact, but the very high EPSS score and wide deployment of ISC DHCP raise the practical risk.
What it is
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 fails to properly validate the length field in a UDP IPv4 packet, allowing a remote attacker to crash the DHCP service. Because DHCP is a core network service, a crash can disrupt address assignment for clients on the affected segment.
Impact
An attacker can cause the DHCP daemon to crash, producing a denial of service. The CVSS vector shows only availability impact (A:H) with no confidentiality or integrity loss.
Attack surface
The flaw is reached over an adjacent network via a crafted UDP IPv4 packet, per the CVSS vector AV:A. No authentication or user interaction is required (PR:N, UI:N).
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.827 (99.65th percentile), indicating elevated likelihood of exploitation activity. References are advisory and mailing-list entries only, with no public exploit tag.
What to do
- Upgrade ISC DHCP to 4.1-ESV-R12-P1, 4.3.3-P1 or later as applicable to your branch.
- Apply vendor updates for Debian, Ubuntu, Oracle and Sophos UTM up2date packages listed in the references.
- Restrict DHCP traffic to trusted network segments and block UDP port 67/68 from untrusted sources at network boundaries.
- Monitor DHCP service availability and configure automatic restart or failover to limit outage duration.
Detection
- Alert on unexpected DHCP daemon crashes or restarts in system and service logs.
- Monitor for malformed or anomalous UDP IPv4 packets with invalid length fields directed at DHCP ports 67/68.
- Track DHCP service availability gaps that could indicate a successful denial-of-service attempt.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-8605 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-8605), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.