Impact
This vulnerability is an input validation flaw (CWE‑20) that permits an unauthenticated attacker connected to a client‑facing VLAN to send a specially crafted DHCP packet containing Option 82. The packet forces the DHCP Relay service to restart, resulting in a denial‑of‑service that disrupts DHCP provisioning for all hosts on the affected VLAN and can cripple network connectivity for many devices.
Affected Systems
Arista Networks EOS devices running any version prior to the remediated releases are impacted. The fix is available in EOS version 4.35.6M and later releases in the 4.35.x train, EOS 4.34.8M and later releases in the 4.34.x train, and EOS 4.33.10M and later releases in the 4.33.x train.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability carries a medium‑high risk. The EPSS score of less than 1 % indicates that exploitation is presently rare, and it is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is local over the network; an attacker who can send packets to a client‑facing VLAN’s DHCP relay component can trigger the exploit without authentication or privileged access.
OpenCVE Enrichment