DHCP Relay Vulnerability in Arista EOS Affects Network Security
CVE-2026-19655
7.1HIGH
What is CVE-2026-19655?
A vulnerability exists on platforms using Arista EOS that have Dynamic Host Configuration Protocol (DHCP) relay or snooping enabled, particularly when configured with the information option (Option 82). An unauthenticated attacker could exploit this flaw by sending crafted packets over client-facing VLANs where the DHCP relay is set up, leading to a restart of the DHCP Relay service. This situation can expose the network to further risks and disrupt service continuity.
Affected Version(s)
EOS 710 Series 4.35.0 <= 4.35.5M
EOS 710 Series 4.34.0 <= 4.34.7.1M
EOS 710 Series 4.33.0 <= 4.33.9M
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered internally by Arista.
