Description
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.
Published: 2026-09-14
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Potential traffic exposure via ACL bypass during supplicant removal
Action: Patch
AI Analysis

Impact

An authenticated supplicant may experience a brief period—from milliseconds to seconds—after the device removes the session, either through the clear dot1x host all CLI command or due to a timeout. During that window, any data sent by the supplicant can pass through the switch without the ACLs that were previously enforcing security. The flaw does not allow arbitrary code execution or privilege escalation, but it can leak traffic that was intended to be filtered, thereby exposing confidential data or allowing content to bypass intended security controls.

Affected Systems

Arista Networks EOS platforms are affected. All 4.x train releases older than 4.36.2F, 4.35.6M, 4.34.8M, or 4.33.10M contain the issue. Versions released in those or later builds in each train contain the fix.

Risk and Exploitability

The CVSS score of 2.1 indicates a low overall severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated supplicant to be forcibly removed; otherwise, an unauthenticated actor cannot trigger the traffic leak. The impact is limited to a temporary bypass of ACLs, but it could lead to accidental disclosure of data passing through the switch during the removal window.

Generated by OpenCVE AI on September 17, 2026 at 18:59 UTC.

Remediation

Vendor Solution

CVE-2026-75943 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train. * 4.35.6M and later releases in the 4.35.x train. * 4.34.8M and later releases in the 4.34.x train. * 4.33.10M and later releases in the 4.33.x train.


Vendor Workaround

There is no workaround available for CVE-2026-75943.


OpenCVE Recommended Actions

  • Upgrade the EOS firmware to at least version 4.36.2F or the corresponding 4.35.6M, 4.34.8M, or 4.33.10M releases in each train, which contain the fix
  • If an upgrade cannot be performed immediately, review and tighten ACLs to minimize the risk of exposing sensitive data during any brief window of traffic flow, and monitor authentication events for abrupt session terminations
  • Use network monitoring tools to detect any anomalous traffic during supplicant removal events, and consider disabling the clear dot1x host all command or enforcing stricter timeout settings until the issue is resolved

Generated by OpenCVE AI on September 17, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.
Title A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcem
Weaknesses CWE-459
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-15T13:48:21.268Z

Reserved: 2026-08-18T16:04:10.264Z

Link: CVE-2026-75943

cve-icon Vulnrichment

Updated: 2026-09-15T13:48:17.439Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T23:18:35.457

Modified: 2026-09-16T20:36:52.890

Link: CVE-2026-75943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses