| MAC flooding | The switch's address table fills, and it floods frames out every port like a hub | A finite address table that learns any source address | A burst of new hardware addresses on one port, table at capacity | Port security (cap addresses per port) |
|---|
| DHCP starvation | The lease pool runs dry, and new clients get no address | DHCP serves any requester | Pool exhaustion, many client identifiers behind one port | Port security, DHCP snooping |
|---|
| Rogue DHCP server | Clients receive a bogus gateway or DNS server, putting a third party in the path | Clients accept the first offer they get | Offers from a server nobody registered, clients with unexpected gateways | DHCP snooping |
|---|
| ARP poisoning | Hosts map a trusted IP (often the gateway) to the wrong hardware address, putting a third party in the path | ARP is stateless and unauthenticated | A critical IP's hardware address changes in host tables, duplicate-address alerts | Dynamic ARP Inspection, static entries for critical hosts |
|---|
| MAC spoofing | A device borrows another device's hardware address to inherit its access | Access decisions made on hardware address alone | A known address showing a device profile that does not match the asset record | 802.1X port authentication instead of MAC filtering |
|---|
| DNS poisoning | A correct name resolves to an attacker-chosen address | Resolvers that accept unauthenticated answers | Answers that differ from the authoritative zone, users meeting certificate warnings | DNSSEC validation, hardened resolvers |
|---|
| VLAN hopping | Frames reach a VLAN the port was never assigned to (switch spoofing or double tagging) | Auto-negotiated trunking, a native VLAN shared with users | Trunk negotiation appearing on access ports | Disable trunk negotiation on access ports, unused native VLAN |
|---|
| STP manipulation | A rogue device wins the root-bridge election and traffic reroutes through it | Switches accept bridge protocol messages on any port | Unexpected root-bridge change, topology-change notices | BPDU guard on access ports, root guard |
|---|