{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 156 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24712-security-advisory-0156"
      }
    ],
    "title": "Security Advisory 156",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:12Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 156",
      "initial_release_date": "2026-09-17T11:48:12Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:12Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.2",
                    "product": {
                      "name": "EOS version 4.36.2",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 1.0.0",
                    "product": {
                      "name": "EOS version 1.0.0",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.10",
                    "product": {
                      "name": "EOS version 4.33.10",
                      "product_id": "CSAFPID-5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73437",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1869660"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could allow the attacker to supply clients with malicious network configuration parameters, potentially resulting in traffic interception or denial of service for affected clients.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "To be vulnerable to CVE-2026-73437, the DHCP relay must be configured, and either an IPv4 or IPv6 helper address must be configured for the DHCP relay to be active.\n\nE.g., Configuring an IPv4 helper address\n\nE.g., Configuring an IPv6 helper address\n\nThe above config can be validated as mentioned below:\n\nIf DHCP relay is not active (no helper addresses), there is no exposure to this issue:",
          "title": "1869660: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-4",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73437",
          "summary": "MITRE"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "IP Locking can be run in a locked address enforcement disabled state, along with the DHCP Relay, to provide protection against rogue DHCP servers and spoofing. This is supported on DHCPv4 starting with EOS-4.29.0F and on DHCPv6 starting with EOS-4.27.0F. For more information, see [IP Locking](https://www.arista.com/en/support/toi/eos-4-25-1f/14628-ip-locking-release-updates). \n\nThis is compatible with the following platforms only:\n\n* CCS-720XP\n* CCS-710P\n* CCS-720DP\n* CCS-722XPM\n* DCS-7010TX\n* DCS-7050CX3\n* DCS-7050SX3\n* CCS-710XP\n* CCS-720DF\n* CCS-720DT\n* CCS-720XDM\n* CCS-720XPM\n* CCS-755\n* CCS-758\n* DCS-7050CX3M\n* DCS-7050TX3\n* DCS-7304\n* DCS-7308\n* 7300X3\n\nUntrusted ports can be locked with the following configuration:\n\nThe above configuration can be validated using the following output:\n\n \n\nWith the above configuration applied, DHCP traffic from untrusted ports can be blocked and the following output reflects the packet drops:\n\nIn releases prior to EOS-4.35.0F, \u201c*`show address locking counters detail`*\u201d command is not available. Instead, run \u201c*`show platform trident tcam detail`*\u201d and search for these IP Locking counters in the output."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.6,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73437"
    }
  ]
}