{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73437","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:39:35.976Z","datePublished":"2026-09-15T21:02:49.314Z","dateUpdated":"2026-09-17T03:57:04.541Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-15T21:02:49.314Z"},"title":"On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper/destinat","datePublic":"2026-09-09T21:02:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-345","description":"CWE-345 Insufficient Verification of Data Authenticity","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-68","descriptions":[{"lang":"en","value":"CAPEC-68 IP Address Spoofing"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange","virtual or physical appliance"],"versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.1F","changes":[{"at":"4.36.2F","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.5M","changes":[{"at":"4.35.6M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.34.0","lessThanOrEqual":"4.34.7.1M","changes":[{"at":"4.34.8M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.33.0","lessThanOrEqual":"4.33.9M","changes":[{"at":"4.33.10M","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious network configuration parameters, potentially resulting in traffic interception or denial of service for affected clients.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious network configuration parameters, potentially resulting in traffic interception or denial of service for affected clients.</p>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24712-security-advisory-0156","tags":["vendor-advisory"]}],"configurations":[{"lang":"en","value":"To be vulnerable to CVE-2026-73437, the DHCP relay must be configured, and either an IPv4 or IPv6 helper address must be configured for the DHCP relay to be active.\n\n\n\nE.g., Configuring an IPv4 helper address:\n\n\n\nswitch# configure terminal\nswitch(config)#int vlan 100\nswitch(config-if-Vl100)#ip helper-address 10.40.2.3\n\n\n\nE.g., Configuring an IPv6 helper address:\n\n\n\nswitch# configure terminal\nswitch(config)#int vlan 100\nswitch(config-if-Vl100)#ipv6 helper-address 3ffe:701:ffff:100::2\n\n\n\nValidation:\n\n\n\nswitch>show ip dhcp relay\nDHCP relay is active\n...\nInterface: Vlan100\n  DHCPv4 servers: 10.40.2.3\n  DHCPv6 servers: 3ffe:701:ffff:100::2\n\n\n\nIf DHCP relay is not active (no helper addresses), there is no exposure to this issue:\n\n\n\nswitch>show ip dhcp relay\nDHCP relay is not active","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>To be vulnerable to CVE-2026-73437, the DHCP relay must be configured, and either an IPv4 or IPv6 helper address must be configured for the DHCP relay to be active.</p><p>E.g., Configuring an IPv4 helper address:</p><pre>switch# configure terminal\nswitch(config)#int vlan 100\nswitch(config-if-Vl100)#ip helper-address 10.40.2.3</pre><p>E.g., Configuring an IPv6 helper address:</p><pre>switch# configure terminal\nswitch(config)#int vlan 100\nswitch(config-if-Vl100)#ipv6 helper-address 3ffe:701:ffff:100::2</pre><p>Validation:</p><pre>switch&gt;show ip dhcp relay\nDHCP relay is active\n...\nInterface: Vlan100\n  DHCPv4 servers: 10.40.2.3\n  DHCPv6 servers: 3ffe:701:ffff:100::2</pre><p>If DHCP relay is not active (no helper addresses), there is no exposure to this issue:</p><pre>switch&gt;show ip dhcp relay\nDHCP relay is not active</pre>"}]}],"workarounds":[{"lang":"en","value":"IP locking can be run in a locked address enforcement disabled state, along with the DHCP Relay, to provide protection against rogue DHCP servers and spoofing. This is supported on DHCPv4 starting with EOS-4.29.0F and on DHCPv6 starting with EOS-4.27.0F. For more information, see  IP Locking https://www.arista.com/en/support/toi/eos-4-25-1f/14628-ip-locking-release-updates .\n\nThis is compatible with the following platforms only:\n\n \n\n  *  CCS-720XP\n  *  CCS-710P\n  *  CCS-720DP\n  *  CCS-722XPM\n  *  DCS-7010TX\n  *  DCS-7050CX3\n  *  DCS-7050SX3\n  *  CCS-710XP\n  *  CCS-720DF\n  *  CCS-720DT\n  *  CCS-720XDM\n  *  CCS-720XPM\n  *  CCS-755\n  *  CCS-758\n  *  DCS-7050CX3M\n  *  DCS-7050TX3\n  *  DCS-7304\n  *  DCS-7308\n  *  7300X3\n\n\n\n\nUntrusted ports can be locked with the following configuration:\n\n\n\nswitch(config)# address locking\nswitch(config-address-locking)# locked-address ipv4 enforcement disabled\nswitch(config-address-locking)# locked-address ipv6 enforcement disabled\n  \nswitch(config)# int et 5\nswitch(config-if-Et5)# address locking ?\n  ipv4  Enable address locking for IPv4\n  ipv6  Enable address locking for IPv6\n  <cr>\nswitch(config-if-Et5)# address locking ipv4\nswitch(config-if-Et5)# address locking ipv6\n\n\n \n\n\n\nThe above configuration can be validated using the following output:\n\n\n\nswitch# show address locking\nIP Locking is active\nLogging events: None\nBindings persistence is enabled\nBindings last backup time: Not Available\nConfigured IPv4 Interfaces:       Et5\nConfigured IPv6 Interfaces:       Et5\nConfigured IPv4 VLANs:\nConfigured IPv6 VLANs:\n  \nInterface Status\nInterface        IPv4       IPv6\n---------------- ---------- -------------------\nEthernet5        yes*       yes*\n  \n* Locked address enforcement is disabled\n\n\n \n\n\n\nWith the above configuration applied, DHCP traffic from untrusted ports can be blocked and the following output reflects the packet drops:\n\n\n\nswitch#show address locking counters detail\nAction                            Count\n--------------------------------- -----\nARP (0.0.0.0) PERMIT                  0\nDHCP from client to server PERMIT     0\nDHCP from server DROP                 4\n\n\n \n\n\n\nIn releases prior to EOS-4.35.0F, “show address locking counters detail” command is not available. Instead, run “show platform trident tcam detail” and grep for these IP Locking counters.\n\n\n\nswitch#show platform trident tcam detail\n=== TCAM detail for switch Linecard0/0 ===\nGroups programmed in IFP\n...\nTCAM group 129 copy 0 in PIPE 0 uses 3 entries and can use up to 12282 more.\n  IP Locking v4 uses 3 entries.\n    0x0000005c            0 hits - Unknown ARP permit rule\n    0x0000005d            0 hits - DHCP permit from client\n    0x00000060            4 hits - DHCP drop from server\nTCAM group 129 copy 1 in PIPE 0 uses 3 entries and can use up to 12282 more.\n  IP Locking v4 uses 3 entries.\n    0x0800005c            0 hits - Unknown ARP permit rule\n    0x0800005d            0 hits - DHCP permit from client\n    0x08000060            0 hits - DHCP drop from server","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IP locking can be run in a locked address enforcement disabled state, along with the DHCP Relay, to provide protection against rogue DHCP servers and spoofing. This is supported on DHCPv4 starting with EOS-4.29.0F and on DHCPv6 starting with EOS-4.27.0F. For more information, see <a href=\"https://www.arista.com/en/support/toi/eos-4-25-1f/14628-ip-locking-release-updates\" target=\"_blank\" rel=\"noopener noreferrer\">IP Locking</a>.</p><div>This is compatible with the following platforms only:</div><div>&nbsp;</div><ul><li>CCS-720XP</li><li>CCS-710P</li><li>CCS-720DP</li><li>CCS-722XPM</li><li>DCS-7010TX</li><li>DCS-7050CX3</li><li>DCS-7050SX3</li><li>CCS-710XP</li><li>CCS-720DF</li><li>CCS-720DT</li><li>CCS-720XDM</li><li>CCS-720XPM</li><li>CCS-755</li><li>CCS-758</li><li>DCS-7050CX3M</li><li>DCS-7050TX3</li><li>DCS-7304</li><li>DCS-7308</li><li>7300X3</li></ul><p>Untrusted ports can be locked with the following configuration:</p><pre>switch(config)# address locking\nswitch(config-address-locking)# locked-address ipv4 enforcement disabled\nswitch(config-address-locking)# locked-address ipv6 enforcement disabled\n  \nswitch(config)# int et 5\nswitch(config-if-Et5)# address locking ?\n&nbsp;&nbsp;ipv4&nbsp; Enable address locking for IPv4\n&nbsp;&nbsp;ipv6&nbsp; Enable address locking for IPv6\n&nbsp;&nbsp;&lt;cr&gt;\nswitch(config-if-Et5)# address locking ipv4\nswitch(config-if-Et5)# address locking ipv6\n</pre><div>&nbsp;</div><p>The above configuration can be validated using the following output:</p><pre>switch# show address locking\nIP Locking is active\nLogging events: None\nBindings persistence is enabled\nBindings last backup time: Not Available\nConfigured IPv4 Interfaces: &nbsp; &nbsp; &nbsp; Et5\nConfigured IPv6 Interfaces: &nbsp; &nbsp; &nbsp; Et5\nConfigured IPv4 VLANs:\nConfigured IPv6 VLANs:\n  \nInterface Status\nInterface&nbsp; &nbsp; &nbsp; &nbsp; IPv4 &nbsp; &nbsp; &nbsp; IPv6\n---------------- ---------- -------------------\nEthernet5&nbsp; &nbsp; &nbsp; &nbsp; yes* &nbsp; &nbsp; &nbsp; yes*\n  \n* Locked address enforcement is disabled\n</pre><div>&nbsp;</div><p>With the above configuration applied, DHCP traffic from untrusted ports can be blocked and the following output reflects the packet drops:</p><pre>switch#show address locking counters detail\nAction&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Count\n--------------------------------- -----\nARP (0.0.0.0) PERMIT&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0\nDHCP from client to server PERMIT &nbsp; &nbsp; 0\nDHCP from server DROP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 4\n</pre><div>&nbsp;</div><p>In releases prior to EOS-4.35.0F, “<b>show address locking counters detail</b>” command is not available. Instead, run “<b>show platform trident tcam detail</b>” and grep for these IP Locking counters.</p><pre>switch#show platform trident tcam detail\n=== TCAM detail for switch Linecard0/0 ===\nGroups programmed in IFP\n...\nTCAM group 129 copy 0 in PIPE 0 uses 3 entries and can use up to 12282 more.\n&nbsp;&nbsp;IP Locking v4 uses 3 entries.\n&nbsp;&nbsp;&nbsp;&nbsp;0x0000005c&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0 hits - Unknown ARP permit rule\n&nbsp;&nbsp;&nbsp;&nbsp;0x0000005d&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0 hits - DHCP permit from client\n&nbsp;&nbsp;&nbsp;&nbsp;0x00000060&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 4 hits - DHCP drop from server\nTCAM group 129 copy 1 in PIPE 0 uses 3 entries and can use up to 12282 more.\n&nbsp;&nbsp;IP Locking v4 uses 3 entries.\n&nbsp;&nbsp;&nbsp;&nbsp;0x0800005c&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0 hits - Unknown ARP permit rule\n&nbsp;&nbsp;&nbsp;&nbsp;0x0800005d&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0 hits - DHCP permit from client\n&nbsp;&nbsp;&nbsp;&nbsp;0x08000060&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0 hits - DHCP drop from server</pre>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience and enable the reply source-address validation CLI knob under dhcp relay mode:\n\n\n\nswitch(config)# dhcp relay\nswitch(config-dhcp-relay)# reply source-address validation\n\n\n\nCVE-2026-73437 has been fixed in the following releases:\n\n  *  4.36.2F and later releases in the 4.36.x train\n  *  4.35.6M and later releases in the 4.35.x train\n  *  4.34.8M and later releases in the 4.34.x train\n  *  4.33.10M and later releases in the 4.33.x train\n\n\n\n\nNote: All versions require upgrading to a release containing the fix (as listed above) and applying the required configuration. Arista will not be providing any hotfixes.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience and enable the reply source-address validation CLI knob under dhcp relay mode:</p><pre>switch(config)# dhcp relay\nswitch(config-dhcp-relay)# reply source-address validation</pre><p>CVE-2026-73437 has been fixed in the following releases:</p><ul><li>4.36.2F and later releases in the 4.36.x train</li><li>4.35.6M and later releases in the 4.35.x train</li><li>4.34.8M and later releases in the 4.34.x train</li><li>4.33.10M and later releases in the 4.33.x train</li></ul><p><strong>Note:</strong> All versions require upgrading to a release containing the fix (as listed above) and applying the required configuration. Arista will not be providing any hotfixes.</p>"}]}],"credits":[{"lang":"en","value":"This issue was discovered internally by Arista.","type":"finder"}],"source":{"defect":["1869660"],"advisory":"156","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"},"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"CRITICAL","baseScore":9.6,"vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","subIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.5,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H"}}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-73437"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T03:57:04.541Z"}}]}}