Database/Firmware, BMC & network fabric

Arista EOS (802.1X on access/trunk ports): TENANT ISOLATION: with 802.1X configured on access or trunk ports
Impact
TENANT ISOLATION: with 802.1X configured on access or trunk ports and routing enabled on the access VLAN, a malicious supplicant can skip 802.1X authentication entirely. Port-based admission control is what stops an unauthorized machine being plugged into a rack and joining the fabric — this makes it optional. Companion issue CVE-2024-6858 does the same thing in multi-auth mode via a device in the fallback VLAN.
Who can reach it
A device physically connected to a switch port that has 802.1X configured. Colocation, shared cages, and contractor rack-and-stack are the realistic scenarios.
What to do
EOS upgrade plus reload. Do not rely on 802.1X alone as the tenant admission boundary; combine it with per-port VLAN pinning and MAC allowlisting (live config) so a bypassed supplicant still lands nowhere useful.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.