{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 149 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24705-security-advisory-0149"
      }
    ],
    "title": "Security Advisory 149",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:11Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 149",
      "initial_release_date": "2026-09-17T11:48:11Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:11Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.2",
                    "product": {
                      "name": "EOS version 4.36.2",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.0",
                    "product": {
                      "name": "EOS version 4.34.0",
                      "product_id": "CSAFPID-3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73449",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1697784"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with both 802.1X port authentication and the\n\nRADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions.\n\nThis allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network.\n\nBoth 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73449, both of the following conditions must be met:\n\n1. 802.1X must be enabled with RADIUS dynamic authorization\n\nThe running configuration must contain `dot1x system-auth-control` and `dot1x dynamic-authorization`, with one or more interfaces configured for authentication:\n\nAuthenticated 802.1X sessions can be listed with:\n\n2. RADIUS proxy must be enabled with dynamic authorization\n\nThe running configuration contains a `radius proxy` section with at least one client group and the `dynamic-authorization` command:\n\nThe state of the RADIUS proxy feature can be confirmed with:\n\nIf the output of this command shows \"Dynamic authorization: disabled\", or if either the `radius proxy` section or the 802.1X configuration above is absent, there is no exposure to the issue.",
          "title": "1697784: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73449"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.34.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "If the RADIUS proxy dynamic authorization function is not operationally required, disabling it removes the exposure. Please note this operation will stop the switch from forwarding CoA and Disconnect requests to downstream RADIUS proxy clients. Dynamic authorization of the switch's own local 802.1X sessions continues to work.\n\nIf RADIUS proxy dynamic authorization must remain enabled, the exposure window can be reduced (but not eliminated) by lowering the proxy client session idle timeout from its default of 600 seconds:\n\nNote that if the idle-timeout is being reduced, then radius proxy clients should increase the frequency of interim-update accounting requests. For more information about idle-timeout configuration see \u201cConfiguring session idle-timeout\u201d section in [RADIUS Proxy](https://www.arista.com/en/support/toi/eos-4-31-2f/19037-radius-proxy).\n\nIf a specific endpoint must be forcibly disconnected while this issue is unresolved, the following command can be used."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-3",
            "CSAFPID-1",
            "CSAFPID-2",
            "CSAFPID-0"
          ]
        }
      ],
      "title": "CVE-2026-73449"
    }
  ]
}