CVE-2026-75943

Summary

A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.36.0 <= 4.36.1Faffected
Arista NetworksEOS4.35.0 <= 4.35.5Maffected
Arista NetworksEOS4.34.0 <= 4.34.7.1Maffected
Arista NetworksEOS0.0.0 <= 4.33.9Maffected

Weaknesses

  • CWE-459: CWE-459 Incomplete Cleanup

Workarounds

There is no workaround available for CVE-2026-75943.

References