Executive brief
The Address Resolution Protocol (ARP), a fundamental technology used to connect IP addresses to physical hardware addresses on local networks, contains a design flaw that allows any device on the network to impersonate another. By sending fraudulent messages, an attacker can intercept private data, modify network traffic, or completely disconnect users from the internet or internal services. This is a foundational networking issue that affects almost all local area networks (LANs) and can lead to significant data breaches or operational downtime if the local network is not properly secured.
Technical details
The Address Resolution Protocol (ARP) is stateless, meaning hosts will accept and cache ARP replies even if they did not send a corresponding request. An attacker on the same local network (Layer 2) can send unsolicited ARP replies to a victim, mapping a legitimate IP address (such as the default gateway) to the attacker's MAC address. This 'cache poisoning' allows the attacker to perform Man-in-the-Middle (MitM) attacks to sniff or alter traffic, or conduct Denial of Service (DoS) by mapping IPs to non-existent MAC addresses. Because this is a protocol-level design flaw rather than a software bug, it affects all standard implementations of ARP unless mitigated by external security features like Dynamic ARP Inspection (DAI) or static ARP entries.
Affected products
- Generic ARP Protocol All versions supporting ARP (RFC 826)
Timeline
- 1997-09-19: disclosed: Initial disclosure on Bugtraq by Yuri Volobuev.