{"api_version":"1","generated_at":"2026-09-15T12:06:57+00:00","cve":"CVE-2026-73449","urls":{"html":"https://cve.report/CVE-2026-73449","api":"https://cve.report/api/cve/CVE-2026-73449.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-73449","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-73449"},"summary":{"title":"On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI","description":"On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions.\nThis allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network.\nBoth 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue.\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","state":"PUBLISHED","assigner":"Arista","published_at":"2026-09-14 22:16:57","updated_at":"2026-09-14 22:16:57"},"problem_types":["CWE-290","CWE-290 CWE-290 Authentication Bypass by Spoofing"],"metrics":[{"version":"4.0","source":"psirt@arista.com","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"5.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":5.9,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"psirt@arista.com","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L","data":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L","version":"3.1"}}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24705-security-advisory-0149","name":"https://www.arista.com/en/support/advisories-notices/security-advisory/24705-security-advisory-0149","refsource":"psirt@arista.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73449","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73449","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.36.0 4.36.1F custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.35.0 4.35.5M custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.34.0 4.34.7.1M custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\nCVE-2026-73449 has been fixed in the following releases:\n- 4.36.2F and later releases in the 4.36.x train\n- 4.35.6M and later releases in the 4.35.x train\n- 4.34.8M and later releases in the 4.34.x train","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"If the RADIUS proxy dynamic authorization function is not operationally required, disabling it removes the exposure. Please note this operation will stop the switch from forwarding CoA and Disconnect requests to downstream RADIUS proxy clients. Dynamic authorization of the switch's own local 802.1X sessions continues to work.\n\nswitch(config)# radius proxy\nswitch(config-radius-proxy)# no dynamic-authorization\n\nIf RADIUS proxy dynamic authorization must remain enabled, the exposure window can be reduced (but not eliminated) by lowering the proxy client session idle timeout from its default of 600 seconds:\n\nswitch(config)# radius proxy\nswitch(config-radius-proxy)# client session idle-timeout <seconds> seconds\n\nNote that if the idle-timeout is being reduced, then radius proxy clients should increase the frequency of interim-update accounting requests. For more information about idle-timeout configuration see “Configuring session idle-timeout” section in RADIUS Proxy.\nIf a specific endpoint must be forcibly disconnected while this issue is unresolved, the following command can be used.\n\nswitch(config)# clear dot1x host mac <endpoint macAddress>","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"EOS","vendor":"Arista Networks","versions":[{"lessThanOrEqual":"4.36.1F","status":"affected","version":"4.36.0","versionType":"custom"},{"lessThanOrEqual":"4.35.5M","status":"affected","version":"4.35.0","versionType":"custom"},{"lessThanOrEqual":"4.34.7.1M","status":"affected","version":"4.34.0","versionType":"custom"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>\nIn order to be vulnerable to CVE-2026-73449, both of the following conditions must be met:\n1. 802.1X must be enabled with RADIUS dynamic authorization\nThe running configuration must contain dot1x system-auth-control and dot1x dynamic-authorization, with one or more interfaces configured for authentication:\nswitch# show running-config section dot1x\n   dot1x system-auth-control\n   dot1x dynamic-authorization\n   ...\n   interface Ethernet1\n      dot1x pae authenticator\n      dot1x port-control auto\n\nAuthenticated 802.1X sessions can be listed with:\nswitch#show dot1x hosts\n   Port Supplicant MAC Username Auth State Fallback VLAN VLAN Name\n   Et30 0017.0100.0001 00:17:01:00:00:01 MBA SUCCESS NONE 30* VLAN0030\n   Et30 606b.5ba7.73c5 60:6b:5b:a7:73:c5 MBA SUCCESS NONE 30* VLAN0030\n\n2. RADIUS proxy must be enabled with dynamic authorization\nThe running configuration contains a radius proxy section with at least one client group and the dynamic-authorization command:\nswitch# show running-config section radius proxy\n   radius proxy\n      dynamic-authorization\n      client group CG1\n         client ipv4 10.0.0.0/24 vrf default\n         server group SG1\n\nThe state of the RADIUS proxy feature can be confirmed with:\nswitch# show radius proxy client group\n   Radius Client Group : CG1\n   Last time counters were cleared : never\n   Dynamic authorization : enabled\n   Dynamic authorization destination port : &lt;portNumber&gt;\n      Client : &lt;clientName&gt;, authentication port 1812, accounting port 1813, vrf default\n      Resolved IP address : &lt;resolvedIp&gt;\n   …\n\nIf the output of this command shows \"Dynamic authorization: disabled\", or if either the radius proxy section or the 802.1X configuration above is absent, there is no exposure to the issue.\n</pre>"}],"value":"In order to be vulnerable to CVE-2026-73449, both of the following conditions must be met:\n1. 802.1X must be enabled with RADIUS dynamic authorization\nThe running configuration must contain dot1x system-auth-control and dot1x dynamic-authorization, with one or more interfaces configured for authentication:\nswitch# show running-config section dot1x\n   dot1x system-auth-control\n   dot1x dynamic-authorization\n   ...\n   interface Ethernet1\n      dot1x pae authenticator\n      dot1x port-control auto\n\nAuthenticated 802.1X sessions can be listed with:\nswitch#show dot1x hosts\n   Port Supplicant MAC Username Auth State Fallback VLAN VLAN Name\n   Et30 0017.0100.0001 00:17:01:00:00:01 MBA SUCCESS NONE 30* VLAN0030\n   Et30 606b.5ba7.73c5 60:6b:5b:a7:73:c5 MBA SUCCESS NONE 30* VLAN0030\n\n2. RADIUS proxy must be enabled with dynamic authorization\nThe running configuration contains a radius proxy section with at least one client group and the dynamic-authorization command:\nswitch# show running-config section radius proxy\n   radius proxy\n      dynamic-authorization\n      client group CG1\n         client ipv4 10.0.0.0/24 vrf default\n         server group SG1\n\nThe state of the RADIUS proxy feature can be confirmed with:\nswitch# show radius proxy client group\n   Radius Client Group : CG1\n   Last time counters were cleared : never\n   Dynamic authorization : enabled\n   Dynamic authorization destination port : <portNumber>\n      Client : <clientName>, authentication port 1812, accounting port 1813, vrf default\n      Resolved IP address : <resolvedIp>\n   …\n\nIf the output of this command shows \"Dynamic authorization: disabled\", or if either the radius proxy section or the 802.1X configuration above is absent, there is no exposure to the issue."}],"credits":[{"lang":"en","type":"finder","value":"This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."}],"datePublic":"2026-09-09T21:54:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions.\nThis allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network.\nBoth 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue.\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n</pre>"}],"value":"On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions.\nThis allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network.\nBoth 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue.\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":5.9,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-290","description":"CWE-290 Authentication Bypass by Spoofing","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-14T21:57:39.220Z","orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista"},"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24705-security-advisory-0149"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\nCVE-2026-73449 has been fixed in the following releases:\n- 4.36.2F and later releases in the 4.36.x train\n- 4.35.6M and later releases in the 4.35.x train\n- 4.34.8M and later releases in the 4.34.x train\n</pre>"}],"value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\nCVE-2026-73449 has been fixed in the following releases:\n- 4.36.2F and later releases in the 4.36.x train\n- 4.35.6M and later releases in the 4.35.x train\n- 4.34.8M and later releases in the 4.34.x train"}],"source":{"advisory":"149","defect":["1697784"],"defects":["BUG 1697784"],"discovery":"INTERNAL"},"title":"On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>\nIf the RADIUS proxy dynamic authorization function is not operationally required, disabling it removes the exposure. Please note this operation will stop the switch from forwarding CoA and Disconnect requests to downstream RADIUS proxy clients. Dynamic authorization of the switch's own local 802.1X sessions continues to work.\n\nswitch(config)# radius proxy\nswitch(config-radius-proxy)# no dynamic-authorization\n\nIf RADIUS proxy dynamic authorization must remain enabled, the exposure window can be reduced (but not eliminated) by lowering the proxy client session idle timeout from its default of 600 seconds:\n\nswitch(config)# radius proxy\nswitch(config-radius-proxy)# client session idle-timeout &lt;seconds&gt; seconds\n\nNote that if the idle-timeout is being reduced, then radius proxy clients should increase the frequency of interim-update accounting requests. For more information about idle-timeout configuration see “Configuring session idle-timeout” section in RADIUS Proxy.\nIf a specific endpoint must be forcibly disconnected while this issue is unresolved, the following command can be used.\n\nswitch(config)# clear dot1x host mac &lt;endpoint macAddress&gt;\n</pre>"}],"value":"If the RADIUS proxy dynamic authorization function is not operationally required, disabling it removes the exposure. Please note this operation will stop the switch from forwarding CoA and Disconnect requests to downstream RADIUS proxy clients. Dynamic authorization of the switch's own local 802.1X sessions continues to work.\n\nswitch(config)# radius proxy\nswitch(config-radius-proxy)# no dynamic-authorization\n\nIf RADIUS proxy dynamic authorization must remain enabled, the exposure window can be reduced (but not eliminated) by lowering the proxy client session idle timeout from its default of 600 seconds:\n\nswitch(config)# radius proxy\nswitch(config-radius-proxy)# client session idle-timeout <seconds> seconds\n\nNote that if the idle-timeout is being reduced, then radius proxy clients should increase the frequency of interim-update accounting requests. For more information about idle-timeout configuration see “Configuring session idle-timeout” section in RADIUS Proxy.\nIf a specific endpoint must be forcibly disconnected while this issue is unresolved, the following command can be used.\n\nswitch(config)# clear dot1x host mac <endpoint macAddress>"}],"x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","assignerShortName":"Arista","cveId":"CVE-2026-73449","datePublished":"2026-09-14T21:57:39.220Z","dateReserved":"2026-08-12T16:42:47.921Z","dateUpdated":"2026-09-14T21:57:39.220Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-14 22:16:57","lastModifiedDate":"2026-09-14 22:16:57","problem_types":["CWE-290","CWE-290 CWE-290 Authentication Bypass by Spoofing"],"metrics":{"cvssMetricV40":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":4.7}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"73449","Ordinal":"1","Title":"On affected platforms running Arista EOS with both 802.1X port a","CVE":"CVE-2026-73449","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"73449","Ordinal":"1","NoteData":"On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions.\nThis allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network.\nBoth 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue.\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","Type":"Description","Title":"On affected platforms running Arista EOS with both 802.1X port a"}]}}}