在受影响的平台上,如果 Arista EOS 同时配置了 802.1X 端口认证和启用了动态授权的 RADIUS 代理功能,位于相邻网络段的低权限攻击者可以通过已配置的 RADIUS 代理客户端触发 RADIUS 数据包,从而阻止 RADIUS 动态授权消息(包括 RFC 5176 中定义的变更授权(Change-of-Authorization, CoA)和断开请求(Disconnect-Requests))作用于本地已认证的 802.1X 会话。 这使得被 RADIUS 服务器或网络访问控制系统下令断开的终端会
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | EOS | 4.36.0 ~ 4.36.1F | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75943 | 2.6 LOW | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant |
| CVE-2026-75944 | 2.6 LOW | A race condition during supplicant re-authentication may leave a stale ACL entry that pers |
| CVE-2026-77191 | 2.6 LOW | All of the CVEs covered in this advisory apply to affected platforms running Arista EOS wi |
| CVE-2026-75945 | 2.6 LOW | A race condition may cause a supplicant to remain in an authorized state after a clear dot |
No comments yet