DHCP Relay Vulnerability in Arista EOS Affects Network Security
CVE-2026-19655

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-19655?

A vulnerability exists on platforms using Arista EOS that have Dynamic Host Configuration Protocol (DHCP) relay or snooping enabled, particularly when configured with the information option (Option 82). An unauthenticated attacker could exploit this flaw by sending crafted packets over client-facing VLANs where the DHCP relay is set up, leading to a restart of the DHCP Relay service. This situation can expose the network to further risks and disrupt service continuity.

Affected Version(s)

EOS 710 Series 4.35.0 <= 4.35.5M

EOS 710 Series 4.34.0 <= 4.34.7.1M

EOS 710 Series 4.33.0 <= 4.33.9M

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered internally by Arista.
.