Impact
A low‑privileged attacker on an adjacent network segment can inject a crafted RADIUS packet through a configured RADIUS proxy client. The vulnerability prevents the system from applying RADIUS dynamic‑authorization messages—including Change‑of‑Authorization and Disconnect‑Requests— to locally authenticated 802.1X sessions. As a result, a session that a RADIUS server or network access control system has ordered to be disconnected can continue to stay authorized on the network, allowing an attacker to retain unauthorized network access.
Affected Systems
Arista Networks EOS platforms are affected. Vulnerable releases include the 4.36.x series from 4.36.2F and later, the 4.35.x series from 4.35.6M and later, and the 4.34.x series from 4.34.8M and later.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate to high level of vulnerability. No EPSS data is available, suggesting a low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The attack vector requires an attacker to be on an adjacent network segment and to have the ability to deliver a RADIUS packet; the vulnerability is only exploitable when both 802.1X port authentication and RADIUS proxy dynamic authorization are explicitly configured. Although Arista has found no evidence of malicious exploitation in customer networks, the potential to bypass disconnect requests is significant for environments relying on strict access control.
OpenCVE Enrichment