CVE-2026-73449: On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI

Published Sep 14, 2026
·
Updated

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions. This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network. Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

Affected Software

1 affected component
Arista EOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.34.8M
  2. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.35.6M
  3. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.36.2F
  4. Configuration

    The issue applies only when both 802.1X port authentication with dynamic authorization AND RADIUS proxy with dynamic authorization are explicitly configured; ensure this combined configuration is removed/avoided unless required, and still upgrade to a remediated EOS version at the earliest convenience.

    Arista EOS 802.1X port authentication (dynamic authorization) and RADIUS proxy (dynamic authorization) dynamic authorization exposure condition = Ensure either 802.1X port authentication with dynamic authorization is not exposed or RADIUS proxy with dynamic authorization is not configured for the affected deployment

Event History

Sep 14, 2026
CVE Published
via MITRE·09:57 PM
Data Sourced
via MITRE·09:57 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Exposure requires both 802.1X port authentication with dynamic authorization and the RADIUS proxy feature with dynamic authorization to be explicitly configured. Deployments without this combination are not described as affected.

2

What access does an attacker need?

The attacker must be low privileged, located on an adjacent network segment, and able to induce a RADIUS packet through a configured RADIUS proxy client. No user interaction is required.

3

What is the operational impact of successful exploitation?

RADIUS dynamic authorization messages, including CoA and Disconnect-Requests, may not be applied to locally authenticated 802.1X sessions. An endpoint that the RADIUS server or NAC system has instructed to disconnect can remain authorized on the network.

4

Is there evidence of exploitation in customer environments?

Arista states that it is not aware of malicious exploitation of this vulnerability in customer networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203