CVE-2026-19655
Received Received - Intake

DHCP Relay Service Crash in Arista EOS

Vulnerability report for CVE-2026-19655, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthenticated attacker connected to a client-facing VLAN(s) where the relay is configured can send a specially crafted packet that causes the DHCP Relay service to restart.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista arista_eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices with DHCP relay/snooping configured with the information option (Option 82) or DHCP servers using match criteria based on Option 82. An unauthenticated attacker on a client-facing VLAN can send a crafted packet causing the DHCP Relay service to restart.

Impact Analysis

The restart of the DHCP Relay service may disrupt network connectivity for clients relying on DHCP, leading to temporary loss of network access. This could affect operations dependent on stable DHCP services.

Mitigation Strategies

Disable DHCP relay/snooping with the information option (Option 82) or DHCP server match criteria based on the information option if configured. Update Arista EOS to the latest patched version as soon as possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19655. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart