Impact
A race condition in Arista Networks’ EOS 802.1X management logic can allow a supplicant device to remain in an authorized state even after the "clear dot1x host all" command is executed. The flaw occurs when the command is initiated while the system is concurrently processing another device’s state transition, causing the authenticated status to be preserved for that client. The result is a bypass of the intended authorization enforcement, leaving the device able to send traffic on the network without re‑authentication.
Affected Systems
The vulnerability affects Arista Networks’ EOS 802.1X management in the 4.36.x train, starting with release 4.36.2F. Releases 4.36.2F and later contain the fix that removes the race condition, while earlier releases in that train do not. No other EOS release trains are reported to be affected.
Risk and Exploitability
The CVSS score of 2.1 indicates a low overall severity and the EPSS score is below 1%, implying limited exploitation potential. The likely attack vector is through the device’s local management interface executing the clear dot1x host all command while a race condition exists, which is a very specific and constrained scenario. The vulnerability is not listed in the CISA KEV catalog, and because it only allows an attacker to maintain authentication without re‑verification, it does not pose a direct privilege escalation or service disruption risk.
OpenCVE Enrichment