Junglewise Threat Intelligence

CVE-2026-19655: Arista EOS DHCP relay denial of service via Option 82

CVE-2026-19655 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS network switches contain a vulnerability in the DHCP relay/snooping service that can be exploited by an unauthenticated attacker on the client-facing network to cause the DHCP relay service to crash and restart. When DHCP relay or snooping is configured with Option 82 (information option), a specially crafted packet can trigger a denial of service, temporarily disrupting DHCP address assignment for connected devices until the service recovers.

Technical details

The vulnerability is an improper input validation flaw (CWE-20) in the DHCP relay service that processes DHCP packets containing Option 82 (information option). An unauthenticated attacker connected to a client-facing VLAN where the relay is configured can send a specially crafted DHCP packet that causes the DhcpRelay process to crash and restart. The attack requires either DHCP relay with information option enabled on an interface with helper-address configured, or DHCP snooping with information option enabled. The service automatically restarts after the crash, resulting in a denial of service to DHCP clients during the restart window. No authentication is required and the attack is network-reachable from client VLANs.

Affected products

  • Arista EOS 4.35.5M and below in 4.35.x train, 4.34.7.1M and below in 4.34.x train, 4.33.9M and below in 4.33.x train, and all prior releases

Timeline

  • 2026-09-09: disclosed: Security Advisory 0155 initial release
  • 2026-09-15: advisory: NVD published CVE-2026-19655

References

Related threats