7.1
CVSSv2

CVE-2016-2774

Published: 09/03/2016 Updated: 08/01/2020
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

ISC DHCP 4.1.x prior to 4.1-ESV-R13 and 4.2.x and 4.3.x prior to 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote malicious users to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.

Vulnerable Product Search on Vulmon Subscribe to Product

isc dhcp 4.1-esv

isc dhcp 4.1.0

isc dhcp 4.1.1

isc dhcp 4.1.2

isc dhcp 4.2.0

isc dhcp 4.2.1

isc dhcp 4.2.2

isc dhcp 4.2.3

isc dhcp 4.2.4

isc dhcp 4.2.5

isc dhcp 4.2.6

isc dhcp 4.2.7

isc dhcp 4.2.8

isc dhcp 4.3.0

isc dhcp 4.3.1

isc dhcp 4.3.2

isc dhcp 4.3.3

debian debian linux 8.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

Vendor Advisories

Synopsis Moderate: dhcp security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for dhcp is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ( ...
Debian Bug report logs - #817158 isc-dhcp: CVE-2016-2774: An attacker who is allowed to connect to DHCP inter-server communications and control channels can exhaust server resources Package: src:isc-dhcp; Maintainer for src:isc-dhcp is Debian ISC DHCP Maintainers <isc-dhcp@packagesdebianorg>; Reported by: Salvatore Bonaccor ...
Several security issues were fixed in DHCP ...