在 supplicant(认证客户端)重新认证过程中,竞态条件可能导致系统中残留一个过时的 ACL(访问控制列表)条目。如果 AclAgent(访问控制代理)随后发生重启,这个过时的条目可能会被应用到新的 supplicant 上,从而导致访问控制执行错误。要使这种非预期行为生效,需要用户交互(即管理员手动重启 AclAgent)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | EOS | 4.36.0 ~ 4.36.1F | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73449 | 5.9 MEDIUM | On affected platforms running Arista EOS with both 802.1X port authentication and the RADI |
| CVE-2026-75943 | 2.6 LOW | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant |
| CVE-2026-77191 | 2.6 LOW | All of the CVEs covered in this advisory apply to affected platforms running Arista EOS wi |
| CVE-2026-75945 | 2.6 LOW | A race condition may cause a supplicant to remain in an authorized state after a clear dot |
No comments yet