Home

Description

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.

PUBLISHED Reserved 2023-10-10 | Published 2026-06-04 | Updated 2026-06-05 | Assigner Arista




HIGH: 8.2CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

MEDIUM: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Problem types

CWE-287 Improper Authentication

Product status

Default status
unaffected

4.31.0 (custom)
affected

4.30.0 (custom)
affected

4.29.0 (custom)
affected

4.28.0 (custom)
affected

4.27.0 (custom)
affected

4.26.0 (custom)
affected

4.25.0 (custom)
affected

4.24.0 (custom)
affected

References

www.arista.com/...rity-advisory/19462-security-advisory-0096

cve.org (CVE-2023-5502)

nvd.nist.gov (CVE-2023-5502)

Download JSON