GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: RADIUS proxy suppresses CoA and Disconnect-Requests for local 802.1X sessions

CVSS 5.9CVE-2026-73449Firmware, BMC & network fabriccurated

Impact

On switches configured with both 802.1X dynamic authorization and the RADIUS proxy feature, an attacker on an adjacent segment who induces a RADIUS packet through a configured proxy client can stop RFC 5176 dynamic authorization messages - Change-of-Authorization and Disconnect-Request - from being applied to locally authenticated sessions. The practical effect is that a session the NAC system has ordered off the network stays authorized. Where 802.1X is the control that keeps an untrusted host off the management or storage VLAN of a GPU fleet, the revocation path is the thing that fails, so a host flagged as compromised keeps its access until someone intervenes at the switch. Arista found this internally and reports no known exploitation.

Who can reach it

A low-privileged attacker on an adjacent network segment able to induce a RADIUS packet through a configured RADIUS proxy client. Only deployments that explicitly configure both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization are exposed.

What to do

Check whether both features are configured together; if not, the switch is not exposed and nothing needs scheduling. If it is, follow Arista security advisory 0149 for the fixed EOS releases or hotfix - the record does not name specific versions, so read the advisory for the train you run. A configuration workaround (removing the RADIUS proxy dynamic-authorization combination) avoids an upgrade window; an EOS upgrade means a switch maintenance window on that leaf.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.