Database/Firmware, BMC & network fabric

Arista EOS: brief windows where 802.1X supplicant traffic passes without ACL enforcement
Impact
Arista split three closely related timing defects in 802.1X authorization across CVE-2026-75943, CVE-2026-75945 and CVE-2026-77191 in one advisory, all with the same score and the same fix. Traffic from a supplicant can pass without its assigned ACL for a window of milliseconds to seconds - after an authenticated supplicant is removed by timeout or by clear dot1x host all, and between the completion of authentication and full ACL enforcement - and a race can also leave a supplicant marked authorized after clear dot1x host all. The exposure is a short unfiltered window, not a durable bypass, so the realistic consequence on a fabric is a few packets from a host onto a segment it should not reach. Worth patching on switches where 802.1X separates tenant or management VLANs, not worth an emergency window.
Who can reach it
An authenticated 802.1X supplicant on an adjacent network segment, with low privileges. No user interaction is required, but the attacker must act inside a window of milliseconds to seconds around authentication or session teardown.
What to do
Roll the fixed EOS release or hotfix from Arista security advisory 0150 into the normal switch upgrade cycle; the record does not name fixed versions, so take them from the advisory for your train. Given the low severity and the sub-second window, this does not justify an out-of-band maintenance window on its own - bundle it with CVE-2026-75944 from the same advisory.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Intel TDX firmware: Improper buffer restrictions in TDX firmware reachable by a privileged host user for privilegeCVE-2025-21096 · Intel TDX firmwareLow
- AMD SEV-SNP - selective DMA write drops on host-induced faults: By inducing faults, a high-privileged local attackerCVE-2025-0029 · AMD SEV-SNP - selective DMA write drops on host-induced faultsLow
- AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023): Missing checks around RMP initializationCVE-2025-48509 · AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023)Low
- AMD Secure Processor - incomplete cleanup exposing the Master Encryption Key (AMD-SB-3003): Incomplete cleanup in theCVE-2023-20518 · AMD Secure Processor - incomplete cleanup exposing the Master Encryption Key (AMD-SB-3003)Low
- Lenovo XClarity OneCLI: temp file handling lets a local user overwrite files when the tool runs elevatedCVE-2026-16791 · Lenovo XClarity Essentials OneCLI (Linux, 5.5.0 and below)Low
- Wiwynn / Celestica / Ingrasys (Foxconn) / AIC BMC firmware: This vendor's firmware is unmeasurable from public dataNCVD-2026-015-wiwynn-celestica-ingrasys-foxcon · Wiwynn / Celestica / Ingrasys (Foxconn) / AIC BMC firmwareUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.