GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: brief windows where 802.1X supplicant traffic passes without ACL enforcement

CVSS 2.1CVE-2026-75943Firmware, BMC & network fabric+2 more CVEscurated

Impact

Arista split three closely related timing defects in 802.1X authorization across CVE-2026-75943, CVE-2026-75945 and CVE-2026-77191 in one advisory, all with the same score and the same fix. Traffic from a supplicant can pass without its assigned ACL for a window of milliseconds to seconds - after an authenticated supplicant is removed by timeout or by clear dot1x host all, and between the completion of authentication and full ACL enforcement - and a race can also leave a supplicant marked authorized after clear dot1x host all. The exposure is a short unfiltered window, not a durable bypass, so the realistic consequence on a fabric is a few packets from a host onto a segment it should not reach. Worth patching on switches where 802.1X separates tenant or management VLANs, not worth an emergency window.

Who can reach it

An authenticated 802.1X supplicant on an adjacent network segment, with low privileges. No user interaction is required, but the attacker must act inside a window of milliseconds to seconds around authentication or session teardown.

What to do

Roll the fixed EOS release or hotfix from Arista security advisory 0150 into the normal switch upgrade cycle; the record does not name fixed versions, so take them from the advisory for your train. Given the low severity and the sub-second window, this does not justify an out-of-band maintenance window on its own - bundle it with CVE-2026-75944 from the same advisory.

Also covers 2 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-75945CVE-2026-77191

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.