Impact
Arista EOS DHCP relay lacks source-address validation when a relay is enabled. An unauthenticated attacker with network access can forge a DHCP reply packet from an address that is not listed as a helper address. The relay agent forwards this packet to clients, allowing the attacker to deliver malicious network configuration parameters such as incorrect IPs, gateways, or DNS servers. Consequently, clients may experience traffic interception, misrouting, or denial of service.
Affected Systems
The vulnerability affects Arista Networks EOS firmware versions earlier than the release trains containing the patch: EOS 4.36.2F, 4.35.6M, 4.34.8M, and 4.33.10M and later, respectively in each train. Commonly impacted hardware includes the CCS‑720XP, CCS‑710P, CCS‑720DP, CCS‑722XPM, DCS‑7010TX, DCS‑7050CX3, DCS‑7050SX3, CCS‑710XP, CCS‑720DF, CCS‑720DT, CCS‑720XDM, CCS‑720XPM, CCS‑755, CCS‑758, DCS‑7050CX3M, DCS‑7050TX3, DCS‑7304, DCS‑7308, and 7300X3 models that run EOS.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity, while the EPSS score of <1% indicates a very low probability of exploitation at present. The attack vector is network-based and requires only local or sub-net access to transmit crafted DHCP packets. The vulnerability does not demand privileged credentials, but it relies on the existence of a DHCP relay configuration. Although currently low in exploitation likelihood, the impact on client networks is significant if an attacker succeeds. The CVE is not listed in the CISA KEV catalog.
OpenCVE Enrichment