Description
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthenticated attacker connected to a client-facing VLAN(s) where the relay is configured can send a specially crafted packet that causes the DHCP Relay service to restart.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via DHCP relay service restart
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an input validation flaw (CWE‑20) that permits an unauthenticated attacker connected to a client‑facing VLAN to send a specially crafted DHCP packet containing Option 82. The packet forces the DHCP Relay service to restart, resulting in a denial‑of‑service that disrupts DHCP provisioning for all hosts on the affected VLAN and can cripple network connectivity for many devices.

Affected Systems

Arista Networks EOS devices running any version prior to the remediated releases are impacted. The fix is available in EOS version 4.35.6M and later releases in the 4.35.x train, EOS 4.34.8M and later releases in the 4.34.x train, and EOS 4.33.10M and later releases in the 4.33.x train.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability carries a medium‑high risk. The EPSS score of less than 1 % indicates that exploitation is presently rare, and it is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is local over the network; an attacker who can send packets to a client‑facing VLAN’s DHCP relay component can trigger the exploit without authentication or privileged access.

Generated by OpenCVE AI on September 18, 2026 at 14:11 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-19655 has been fixed in the following releases: * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train * 4.33.10M and later releases in the 4.33.x train


Vendor Workaround

There is no workaround known for this issue.


OpenCVE Recommended Actions

  • Update the device to a fixed release such as 4.35.6 M or later, 4.34.8 M or later, or 4.33.10 M or later.
  • Limit the VLANs on which DHCP relay or snooping is enabled to trusted or required networks only, reducing the surface for potential attackers.
  • Monitor DHCP relay service logs and network traffic for unexpected restarts or unusually crafted DHCP packets to detect exploitation attempts promptly.

Generated by OpenCVE AI on September 18, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthenticated attacker connected to a client-facing VLAN(s) where the relay is configured can send a specially crafted packet that causes the DHCP Relay service to restart.
Title On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthent
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T18:03:27.624Z

Reserved: 2026-08-12T18:51:29.572Z

Link: CVE-2026-19655

cve-icon Vulnrichment

Updated: 2026-09-16T18:03:24.246Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:36.380

Modified: 2026-09-16T19:17:10.360

Link: CVE-2026-19655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:15:09Z

Weaknesses
  • CWE-20

    Improper Input Validation