Port 67: Dynamic Host Configuration Protocol (server port)
UDP port 67 is the DHCP server port. RFC 2131 states that DHCP messages from clients to servers go to the server port (67) and replies go to the client port (68). DHCP servers hand out IP addresses and settings such as DNS servers and default routers; the IANA name bootps comes from the Bootstrap Protocol server role.
Port Details
Security Exposure
DHCP is built on UDP and IP without authentication, and RFC 2131 warns that unauthorized DHCP servers are easy to set up. A rogue server can give clients wrong addresses, spoofed routers, and spoofed DNS servers, which lets an attacker on the local network redirect traffic. A malicious client can also claim every available address and deny service to legitimate clients.
Hardening
- +Enable DHCP snooping on access switches so DHCP server messages arriving on untrusted ports are dropped.
- +Mark only switch ports that face legitimate DHCP servers or relay agents as trusted.
- +In Active Directory domains, authorize Windows DHCP servers so unauthorized servers do not lease addresses.
- +Do not expose UDP 67 to networks outside the subnets the server is meant to serve.
Monitoring
Alert on DHCP offers from unknown server addresses and on large numbers of DHCP requests from one switch port. The DHCP snooping binding database records MAC address, leased IP, port, and VLAN for review.
DHCP Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2017-12240 | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability | - | 9.8 | 13.8% | KEV | 2017-09-28 |
Tools for Auditing and Monitoring DHCP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Related Tool Categories
Frequently Asked Questions
What is the difference between port 67 and 68?→
Port 67 is the DHCP server port and port 68 is the DHCP client port. Clients send to port 67 and servers reply to port 68 (RFC 2131).
Is DHCP TCP or UDP?→
DHCP runs over UDP. RFC 2131 describes it as built directly on UDP and IP, although IANA also lists TCP entries for ports 67 and 68.
What is a rogue DHCP server?→
It is an unauthorized server that answers DHCP requests with false settings such as wrong routers or DNS servers (RFC 2131). DHCP snooping on switches blocks it by dropping server replies from untrusted ports.
Which vulnerabilities affect the service on port 67?→
This database lists 1 CVE related to DHCP, 1 of them confirmed as exploited by CISA. Examples: CVE-2017-12240.
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 67)
- RFC 2131: Dynamic Host Configuration Protocol
- Cisco Catalyst 2960 Software Configuration Guide: Configuring DHCP Features and IP Source Guard
- Microsoft Learn: Deploy DHCP using Windows PowerShell
- Microsoft Learn: Service overview and network port requirements for Windows
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 67 is not guaranteed to be DHCP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).