CVE-2026-73437: On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper/destinat

Published Sep 15, 2026
·
Updated

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious network configuration parameters, potentially resulting in traffic interception or denial of service for affected clients.

Affected Software

1 affected component
Arista Arista EOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.33.10M
  2. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.34.8M
  3. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.35.6M
  4. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.36.2F
  5. Configuration

    Under dhcp relay mode, enable reply source-address validation: use `switch(config)# dhcp relay` then `switch(config-dhcp-relay)# reply source-address validation`.

    Arista EOS DHCP relay reply source-address validation (CLI knob under dhcp relay mode) = enabled

Event History

Sep 15, 2026
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which environments are exposed to this issue?

Affected Arista EOS platforms are exposed when DHCP relay is configured. Clients that receive DHCP replies through the relay may be affected by malicious network configuration parameters.

2

What does an attacker need to exploit it?

An unauthenticated attacker needs network access and must be able to send a crafted DHCP reply packet to the relay. The packet can originate from an IP address that is not configured as a DHCP helper or destination address.

3

What could indicate active exploitation?

Unexpected DHCP-provided network settings on clients, such as altered configuration parameters, may indicate malicious replies were forwarded. Resulting symptoms can include traffic interception or denial of service affecting DHCP clients.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203