GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: DHCP relay forwards replies from unconfigured servers, allowing client config spoofing

CVSS 6.5CVE-2026-73437Firmware, BMC & network fabriccurated

Impact

The relay agent forwards DHCP replies to clients without checking that the reply came from a configured helper address. Anyone who can send packets to the relay can hand hosts a rogue default gateway, DNS server or boot parameters. On a datacenter fabric this is a path to intercepting traffic from freshly provisioned nodes, and where PXE or network boot is involved it influences what a node loads at boot - which is a much worse outcome than plain interception. The scoped-impact metrics in the vector reflect that the damage lands on the client hosts, not on the switch itself.

Who can reach it

Unauthenticated attacker with network access able to send a crafted DHCP reply to the relay agent; no credentials and no management-plane access needed.

What to do

Upgrade to the EOS release or hotfix identified in Arista security advisory 0156 - the record does not name a fixed version. Pending that, DHCP snooping and port-level filtering that drops server-side DHCP traffic from non-server ports limits who can inject replies. Fixing this means a switch maintenance window on every relay-configured switch.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.