Junglewise Threat Intelligence

CVE-2023-5502: Arista EOS 802.1x authentication bypass in access ports

CVE-2023-5502 · Severity: medium · CVSS 5.9 · Published 2026-06-04

Vendors: Arista Networks.

Executive brief

A vulnerability in Arista EOS allows unauthorized devices to bypass 802.1x network admission controls. This security standard is used to ensure only authorized users and devices can connect to the corporate network. An attacker could exploit this to gain unauthorized network access, potentially bypassing perimeter security measures and compromising the integrity of the internal network.

Technical details

An improper authentication vulnerability (CWE-287) exists in Arista EOS when 802.1x authentication is configured on access or trunk ports and routing is enabled on the associated access VLAN. Under these specific conditions, a malicious supplicant can bypass the 802.1x authentication process. The attack vector is network-based, though it requires a high complexity (AC:H) likely due to the specific configuration requirements and timing needed to trigger the bypass. Successful exploitation allows an unauthorized device to gain network connectivity that should have been restricted by port-based NAC.

Affected products

  • Arista Networks EOS

Timeline

  • 2026-06-04: advisory: Security advisory published by Arista Networks

References