CVE-2026-75943: A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcem
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.33.10M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.34.8M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.35.6M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.36.2F
Event History
Frequently Asked Questions
Who is exposed to this issue?
Networks using 802.1X authentication with ACL enforcement for authenticated supplicants are exposed when a supplicant is removed through the clear dot1x host all command or when the supplicant times out.
What must occur for traffic to bypass ACL enforcement?
An authenticated supplicant must be removed, either administratively with clear dot1x host all or as a result of a supplicant timeout. Traffic may pass without ACL enforcement only during the resulting milliseconds-to-seconds window.
What is the practical impact during the affected window?
The supplicant's traffic may be forwarded without ACL enforcement for a brief period. The provided data describes no confidentiality or availability impact, and rates integrity impact as low.