Your network is electing a new Root Bridge right now.

You did not authorize it.

Spanning Tree Protocol has no authentication. Any device on your segment can send a BPDU and reshape your topology. If its priority is low enough, it wins the election. Your traffic reroutes. Silently.

That is the attack.

How STP works: STP prevents Layer 2 loops by electing a Root Bridge — the switch with the lowest Bridge ID (priority + MAC address). All other switches calculate their shortest path to it. Ports are placed in Forwarding or Blocking state. The topology stabilizes. Traffic flows.

Change the Root Bridge, and you change where traffic flows.

How the attack works

  • BPDU SPOOFING An attacker connects a rogue device and crafts BPDUs with a lower bridge priority than your legitimate root. Cisco default is 32768. Setting priority to 0 wins every election unconditionally. The attacker becomes Root Bridge. All inter-switch traffic routes through their device. Full man-in-the-middle at Layer 2. No credentials required.
  • TCN FLOOD Topology Change Notifications trigger MAC table flushes across the switching domain. Flooding TCN packets forces switches to forget learned addresses and revert to broadcasting on every port. Traffic becomes visible to every device on the segment. A passive tap is unnecessary.
  • BPDU FLOODING Malformed BPDUs destabilize spanning tree recalculation, causing ports to cycle between states and inducing outages across affected VLANs.

Real consequences: In 2023, a financial services firm suffered a four-hour outage during trading hours. A misconfigured appliance on an access port transmitted BPDUs with priority 0. It won the Root Bridge election in seconds. Traffic across three VLANs rerouted through a device with insufficient capacity. The appliance was not malicious — the impact was identical to a deliberate attack.

How to defend

BPDU GUARD — Enable on all access ports. Any port receiving a BPDU is immediately placed in err-disabled state. Endpoints cannot participate in STP elections.

PORTFAST — Apply to access ports to skip Listening and Learning states. Combine with BPDU Guard. Never enable on trunk ports.

ROOT GUARD — Apply on ports where a Root Bridge should never appear. Blocks superior BPDUs without disabling the port.

LOOP GUARD — Prevents ports from transitioning to Forwarding if BPDUs stop arriving. Protects against unidirectional link failures misread as topology changes.

RESTRICT STP SCOPE — Use MST or Per-VLAN Spanning Tree. A topology change in one VLAN should not destabilize others.

MONITOR BPDU ACTIVITY — Alert on BPDUs on access ports. Silence is not safety.

STP has run in your network for decades. Most teams configure it once and never revisit it.

Attackers count on that.

Which STP controls are active in your environment today?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.