Impact
An authenticated supplicant on an adjacent network may bypass the intended network authorization policy and send unrestricted traffic during a brief window between authentication completion and ACL enforcement. This allows the supplicant to transmit traffic that would normally be blocked by the per‑supplicant ACL, effectively nullifying the authorization controls for the duration of the window. The weakness is an authentication bypass, identified by CWE‑862.
Affected Systems
The vulnerability affects Arista Networks EOS devices that have 802.1X authentication and authorization enabled with ACLs configured for per‑supplicant policy enforcement. The advisory fixes the issue in EOS release 4.35.1F and later, 4.34.6M and later, and 4.33.8M and later. Systems, 4.34.x or 4.35.x trains remain vulnerable.
Risk and Exploitability
With a CVSS score of 2.1 the risk is low, and the EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability does not appear in the CISA KEV catalog. Because the attacker must be an authenticated supplicant on an adjacent network, the attack vector is internal or semi‑trusted within the local network, and the window for bypass is only milliseconds to seconds. No workaround is provided, so the only reliable protection is to apply the vendor‑issued firmware updates.
OpenCVE Enrichment