Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73449— On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI

Quick assessment

Affected
Arista Networks EOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在受影响的平台上,如果 Arista EOS 同时配置了 802.1X 端口认证和启用了动态授权的 RADIUS 代理功能,位于相邻网络段的低权限攻击者可以通过已配置的 RADIUS 代理客户端触发 RADIUS 数据包,从而阻止 RADIUS 动态授权消息(包括 RFC 5176 中定义的变更授权(Change-of-Authorization, CoA)和断开请求(Disconnect-Requests))作用于本地已认证的 802.1X 会话。 这使得被 RADIUS 服务器或网络访问控制系统下令断开的终端会

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73449

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI
Source: CVE Program / CVE List V5
Vulnerability Description
On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions. This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network. Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Arista Networks EOS 4.36.0 ~ 4.36.1F -

II. Public POCs for CVE-2026-73449

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73449

登录查看更多情报信息。

Vendor Advisories for CVE-2026-73449 (1)

Same Patch Batch · Arista Networks · 2026-09-14 · 5 CVEs total

CVE-2026-75943 2.6 LOW A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant
CVE-2026-75944 2.6 LOW A race condition during supplicant re-authentication may leave a stale ACL entry that pers
CVE-2026-77191 2.6 LOW All of the CVEs covered in this advisory apply to affected platforms running Arista EOS wi
CVE-2026-75945 2.6 LOW A race condition may cause a supplicant to remain in an authorized state after a clear dot

IV. Related Vulnerabilities

V. Comments for CVE-2026-73449

No comments yet


Leave a comment