Impact
An authenticated supplicant may experience a brief period—from milliseconds to seconds—after the device removes the session, either through the clear dot1x host all CLI command or due to a timeout. During that window, any data sent by the supplicant can pass through the switch without the ACLs that were previously enforcing security. The flaw does not allow arbitrary code execution or privilege escalation, but it can leak traffic that was intended to be filtered, thereby exposing confidential data or allowing content to bypass intended security controls.
Affected Systems
Arista Networks EOS platforms are affected. All 4.x train releases older than 4.36.2F, 4.35.6M, 4.34.8M, or 4.33.10M contain the issue. Versions released in those or later builds in each train contain the fix.
Risk and Exploitability
The CVSS score of 2.1 indicates a low overall severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated supplicant to be forcibly removed; otherwise, an unauthenticated actor cannot trigger the traffic leak. The impact is limited to a temporary bypass of ACLs, but it could lead to accidental disclosure of data passing through the switch during the removal window.
OpenCVE Enrichment