CVE-2026-75945

Summary

A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.36.0 <= 4.36.1Faffected

Weaknesses

  • CWE-459: CWE-459 Incomplete Cleanup

Workarounds

For CVE-2026-75945, rerunning the 'clear dot1x host all' command is presented only as conditional mitigation advice when a supplicant remains authenticated.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References