CVE-2023-5502: On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.29.7M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.30.5M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.31.3M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.32.0F
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5502?
The severity of CVE-2023-5502 is rated medium with a score of 5.9.
What is the risk associated with CVE-2023-5502?
CVE-2023-5502 has a risk rating of 35.
How do I fix CVE-2023-5502?
To fix CVE-2023-5502, upgrade to the latest remediated version of Arista EOS.
What platforms are affected by CVE-2023-5502?
CVE-2023-5502 affects platforms running Arista EOS with 802.1x authentication configured on access/trunk ports.
What is the potential impact of CVE-2023-5502?
The potential impact of CVE-2023-5502 is that a malicious supplicant may bypass 802.1x authentication.