Impact
A race condition during supplicant re‑authentication can leave a stale ACL entry in the system. If the Acl be applied to new supplicants, resulting in incorrect assignment of access permissions. The vulnerability could allow an attacker to gain unintended network access by exploiting the stale flaw affects Arista Networks EOS running the 4.36.x train prior to Versions 4.36.2F and later contain the fix and are not vulnerable.
Affected Systems
The vulnerability impacts Arista Networks EOS instances running the 4.36.x train before the 4.36.2F release. Any device in this train that has not applied the fix is vulnerable; later releases such as 4.36.2F or newer contain the patch and are not susceptible.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, but the vulnerability is not listed in CISA KEV. User interaction is required; an administrator must restart the AclAgent for the stale ACL to be re‑ap with accidental or malicious agent restarts, but the potential impact is significant if exploited.
OpenCVE Enrichment