一个经过认证的相邻网络上的请求方(supplicant),可能在身份验证阶段完成与其分配好的访问控制列表(ACL)完全生效之间的短暂时间窗口内(几毫秒到几秒),绕过预设的网络授权策略并发送不受限制的数据流量。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | EOS | 4.35.0 ~ 4.35.0.3F | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73449 | 5.9 MEDIUM | On affected platforms running Arista EOS with both 802.1X port authentication and the RADI |
| CVE-2026-75943 | 2.6 LOW | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant |
| CVE-2026-75944 | 2.6 LOW | A race condition during supplicant re-authentication may leave a stale ACL entry that pers |
| CVE-2026-75945 | 2.6 LOW | A race condition may cause a supplicant to remain in an authorized state after a clear dot |
No comments yet