Database/Firmware, BMC & network fabric

Arista EOS: RADIUS proxy suppresses CoA and Disconnect-Requests for local 802.1X sessions
Impact
On switches configured with both 802.1X dynamic authorization and the RADIUS proxy feature, an attacker on an adjacent segment who induces a RADIUS packet through a configured proxy client can stop RFC 5176 dynamic authorization messages - Change-of-Authorization and Disconnect-Request - from being applied to locally authenticated sessions. The practical effect is that a session the NAC system has ordered off the network stays authorized. Where 802.1X is the control that keeps an untrusted host off the management or storage VLAN of a GPU fleet, the revocation path is the thing that fails, so a host flagged as compromised keeps its access until someone intervenes at the switch. Arista found this internally and reports no known exploitation.
Who can reach it
A low-privileged attacker on an adjacent network segment able to induce a RADIUS packet through a configured RADIUS proxy client. Only deployments that explicitly configure both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization are exposed.
What to do
Check whether both features are configured together; if not, the switch is not exposed and nothing needs scheduling. If it is, follow Arista security advisory 0149 for the fixed EOS releases or hotfix - the record does not name specific versions, so read the advisory for the train you run. A configuration workaround (removing the RADIUS proxy dynamic-authorization combination) avoids an upgrade window; an EOS upgrade means a switch maintenance window on that leaf.
References
Related entries
- Arista EOS (security ACL vs NAT rule interaction): A security ACL drop rule is bypassed when a NAT ACL permit ruleCVE-2021-28511 · Arista EOS (security ACL vs NAT rule interaction)Medium
- AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPSCVE-2021-4228 · AMI MegaRAC SPx 12 (BMC default TLS certificate)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properlyCVE-2021-46279 · AMI MegaRAC SPx 12 / SPx 13 (BMC web session management)Medium
- Tyan S5552 BMC web interface, firmware version 3.00: An unauthenticated attacker downloads the BMC's TLS private keyCVE-2023-2538 · Tyan S5552 BMC web interface, firmware version 3.00Medium
- Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to executeCVE-2024-38490 · Dell iDRAC Service Module (out-of-bounds write)Medium
- Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedCVE-2024-6437 · Arista EOS (PBR / BGP Flowspec / interface traffic policy)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.