{"id":"CVE-2026-19655","title":"On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…","summary":"On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"Arista Networks","product":"EOS","affected":["EOS >= 4.35.0 <= 4.35.5M","EOS >= 4.34.0 <= 4.34.7.1M","EOS >= 4.33.0 <= 4.33.9M"],"published":"2026-09-15","updated":"2026-09-16","sourceUpdated":"2026-09-16T19:17:10.360","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19655","references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24711-security-advisory-0155","label":"psirt@arista.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-16T18:02:48.292435Z"},"ingestedAt":"2026-09-15T21:44:50.634Z","epss":0.00194,"epssPercentile":0.09372,"slug":"CVE-2026-19655","body":"## Overview\n\nOn affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthenticated attacker connected to a client-facing VLAN(s) where the relay is configured can send a specially crafted packet that causes the DHCP Relay service to restart.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}