Skip to main content

Port Details

Port
68
Transport
UDP
Service
DHCP client
IANA service name
bootpc
Range
System port (0-1023)
Related ports

Security Exposure

A DHCP client accepts configuration from whichever server answers, because DHCP has no built-in authentication. RFC 2131 warns that false settings such as spoofed routers and name servers let an attacker compromise affected hosts further. RFC 2131 also notes that unauthorized DHCP servers may be easily set up.

Hardening

  • +Enable DHCP snooping so that only trusted switch ports can deliver server replies to clients.
  • +Segment untrusted devices into separate VLANs to limit how many clients a rogue server can reach.
  • +Use static addressing for servers and network infrastructure that do not need DHCP.
  • +Keep operating systems and DHCP client software patched.

Monitoring

Compare the router and DNS settings handed to clients with the approved configuration, and alert on DHCP replies from server addresses that are not authorized.

DHCP client Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2017-12240
Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
-9.813.8%KEV2017-09-28

Tools for Auditing and Monitoring DHCP client

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is port 68 used by the DHCP server or the client?→

The client. RFC 2131 sends server-to-client DHCP messages to the client port 68, while servers listen on port 67.

Does port 68 need to be open?→

Hosts that get addresses through DHCP must accept replies on UDP 68 from the local DHCP server or relay agent. It has no reason to be reachable from the internet.

Which vulnerabilities affect the service on port 68?→

This database lists 1 CVE related to DHCP client, 1 of them confirmed as exploited by CISA. Examples: CVE-2017-12240.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 68 is not guaranteed to be DHCP client. Exploited-in-the-wild data from the CISA KEV catalog (CC0).