CAPEC Definitions

    CAPEC Definitions / CAPEC-697

    CAPEC-697: DHCP Spoofing

    An adversary masquerades as a legitimate Dynamic Host Configuration Protocol (DHCP) server by spoofing DHCP traffic, with the goal of redirecting network traffic or denying service to DHCP.

    Severity:High
    Possibility:Low

    Extended Description

    DHCP is broadcast to the entire Local Area Network (LAN) and does not have any form of authentication by default. Therefore, it is susceptible to spoofing. An adversary with access to the target LAN can receive DHCP messages; obtaining the topology information required to potentially manipulate other hosts' network configurations. To improve the likelihood of the DHCP request being serviced by the Rogue server, an adversary can first starve the DHCP pool.

    Mitigations

    Design: MAC-Forced Forwarding

    Implementation: Port Security and DHCP snooping

    Implementation: Network-based Intrusion Detection Systems

    Relationships with other CAPECs

    CAPEC-194: Fake the Source of Data

    CAPEC-158: Sniffing Network Traffic

    CAPEC-94: Adversary in the Middle (AiTM)

    Prerequisites

    The adversary must have access to a machine within the target LAN which can send DHCP offers to the target.

    Related Weaknesses

    CWE-923: Improper Restriction of Communication Channel to Intended Endpoints