CVE-2026-73437
Received Received - Intake

DHCP Relay Packet Forwarding in Arista EOS

Vulnerability report for CVE-2026-73437, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious network configuration parameters, potentially resulting in traffic interception or denial of service for affected clients.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista arista_eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices with DHCP relay enabled. An unauthenticated attacker on the network can send a crafted DHCP reply from an untrusted IP address. The DHCP relay agent forwards this packet to clients without checking if the source IP is a configured helper address, potentially allowing malicious network configuration changes.

Detection Guidance

Detecting this vulnerability requires checking Arista EOS devices for DHCP relay configurations and monitoring for unexpected DHCP reply packets. Use commands like 'show running-config | include ip helper-address' to verify DHCP relay settings and 'show ip dhcp relay statistics' to check for anomalies. Monitor network traffic for DHCP replies from untrusted sources using packet capture tools like tcpdump or Wireshark.

Impact Analysis

An attacker could intercept network traffic or disrupt services for affected clients by providing incorrect DNS servers, default gateways, or other network settings. This may lead to data theft, unauthorized access, or denial of service for devices relying on the DHCP relay.

Compliance Impact

This vulnerability could lead to unauthorized network access or data interception, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations if client data is exposed or altered due to the lack of proper DHCP validation.

Mitigation Strategies

Immediately restrict DHCP relay to only accept packets from configured helper addresses. Update Arista EOS to the latest patched version. Implement strict ACLs to block unauthorized DHCP replies. Monitor network traffic for suspicious DHCP activity and isolate affected clients if detected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart