Description
A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
Published: 2026-09-14
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authentication persistence after clearance command
Action: Apply patch
AI Analysis

Impact

A race condition in Arista Networks’ EOS 802.1X management logic can allow a supplicant device to remain in an authorized state even after the "clear dot1x host all" command is executed. The flaw occurs when the command is initiated while the system is concurrently processing another device’s state transition, causing the authenticated status to be preserved for that client. The result is a bypass of the intended authorization enforcement, leaving the device able to send traffic on the network without re‑authentication.

Affected Systems

The vulnerability affects Arista Networks’ EOS 802.1X management in the 4.36.x train, starting with release 4.36.2F. Releases 4.36.2F and later contain the fix that removes the race condition, while earlier releases in that train do not. No other EOS release trains are reported to be affected.

Risk and Exploitability

The CVSS score of 2.1 indicates a low overall severity and the EPSS score is below 1%, implying limited exploitation potential. The likely attack vector is through the device’s local management interface executing the clear dot1x host all command while a race condition exists, which is a very specific and constrained scenario. The vulnerability is not listed in the CISA KEV catalog, and because it only allows an attacker to maintain authentication without re‑verification, it does not pose a direct privilege escalation or service disruption risk.

Generated by OpenCVE AI on September 17, 2026 at 18:58 UTC.

Remediation

Vendor Solution

CVE-2026-75945 has been fixed in the following release: * 4.36.2F and later releases in the 4.36.x train.


Vendor Workaround

For CVE-2026-75945, rerunning the 'clear dot1x host all' command is presented only as conditional mitigation advice when a supplicant remains authenticated.


OpenCVE Recommended Actions

  • Upgrade the device to EOS version 4.36.2F or later to apply the vendor fix for the dot1x race condition.
  • If a supplicant remains authenticated after issuing the clear dot1x host all command, rerun the command to force re‑authentication and clear the persistent session state.
  • Monitor network logs for devices that continue to send traffic after the clearance command.

Generated by OpenCVE AI on September 17, 2026 at 18:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
Title A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
Weaknesses CWE-459
References
Metrics cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-14T23:05:54.600Z

Reserved: 2026-08-18T16:04:12.507Z

Link: CVE-2026-75945

cve-icon Vulnrichment

Updated: 2026-09-14T23:05:51.409Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T23:18:35.970

Modified: 2026-09-16T20:36:52.890

Link: CVE-2026-75945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses