Arista Networks EOS: improper access control
Medium5.9CVE-2026-73449 · Published Sep 14, 2026 · updated Sep 16, 2026
On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions. This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network. Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EOS Product | >= 4.36.0, <= 4.36.1F | No fix yet |
| >= 4.35.0, <= 4.35.5M | No fix yet | |
| >= 4.34.0, <= 4.34.7.1M | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-290
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | On affected platforms running Arista EOS with dual switch cards and with... | Medium6.3 | No fix yet |
| Sep 15 | Arista Networks EOS: improper output encoding | Medium6.9 | No fix yet |
| Sep 14 | Arista Networks EOS: missing authorization | Low2.1 | No fix yet |
| Sep 14 | Arista Networks EOS: incomplete cleanup | Low2.1 | No fix yet |
| Sep 14 | Arista Networks EOS: race condition | Medium5.6 | No fix yet |
| Sep 14 | Arista Networks EOS: race condition | Low2.1 | No fix yet |