Junglewise Threat Intelligence

CVE-2026-73449: Arista EOS RADIUS dynamic authorization bypass

CVE-2026-73449 · Severity: medium · CVSS 5.9 · Published 2026-09-14

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS network switches support 802.1X authentication and RADIUS proxy features used to control which devices can access the network. When both features are enabled with dynamic authorization, an attacker on an adjacent network can craft RADIUS packets to block legitimate disconnection commands, keeping unauthorized or compromised endpoints connected to the network even after a security system has ordered them removed. This could allow a compromised device to remain on the network and continue attacking other systems.

Technical details

This vulnerability is an authentication bypass (CWE-290) affecting Arista EOS's RADIUS proxy and 802.1X dynamic authorization implementation. A low-privileged attacker on an adjacent network segment can induce specially crafted RADIUS packets through a configured RADIUS proxy client to block RADIUS dynamic authorization messages (Change-of-Authorization and Disconnect-Requests per RFC 5176) from being applied to authenticated 802.1X sessions. The attack requires both 802.1X port authentication and RADIUS proxy dynamic authorization to be explicitly configured. Exploitation prevents a RADIUS server or NAC system from disconnecting an endpoint session, allowing unauthorized devices to remain authorized. Patches are available in EOS 4.36.2F, 4.35.6M, and 4.34.8M or later.

Affected products

  • Arista EOS 4.36.1F and below in 4.36.x train, 4.35.5M and below in 4.35.x train, 4.34.7.1M and below in 4.34.x train

Timeline

  • 2026-09-14: disclosed

References

Related threats