{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 150 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24706-security-advisory-0150"
      }
    ],
    "title": "Security Advisory 150",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:11Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 150",
      "initial_release_date": "2026-09-17T11:48:11Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:11Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.6",
                    "product": {
                      "name": "EOS version 4.34.6",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.2",
                    "product": {
                      "name": "EOS version 4.36.2",
                      "product_id": "CSAFPID-6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.10",
                    "product": {
                      "name": "EOS version 4.33.10",
                      "product_id": "CSAFPID-7"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.1",
                    "product": {
                      "name": "EOS version 4.35.1",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 1.0.0",
                    "product": {
                      "name": "EOS version 1.0.0",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-8"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.8",
                    "product": {
                      "name": "EOS version 4.33.8",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-77191",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1108416"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2025-5094, the following condition must be met:\n\nDot1x should be configured for a port as authenticator and port-control must be set to auto mode. Additionally,  ACL\u2019s MUST be configured for this issue to occur.\nswitch(config-if-et1)#show active\n\ninterface Ethernet5\n   switchport mode trunk\n   spanning-tree portfast edge\n   dot1x pae authenticator\n   dot1x port-control auto\n   dot1x mac based access-list\n   dot1x mac based authentication always\n\ndot1x system-auth-control\n\n\nIn this example port control is in \u201cauto\u201d mode, necessary for the condition to occur.\nconfig)#show  dot1x  interface  ethernet  5 details\nDot1X Information for Ethernet5\n--------------------------------------------\nPort control: auto\nForced phone authorization: disabled\nEAPOL: enabled\nHost mode: multi-host\nMAC-based authentication: enabled\nMAC-based authentication host mode: Unconfigured\nMAC-based authentication always: enabled\nQuiet period: 60 seconds\nTX period: 5 seconds\nMaximum reauth requests: 2\nIgnore reauth timeout: No\nAuth failure VLAN: Unconfigured\nUnauthorized access VLAN egress: No\nUnauthorized native VLAN egress: No\nEAPOL authentication failure fallback: Unconfigured\nPort ErrDisabled by CoA: no\n\nDot1X Authenticator Client\n\n\nExample of Sample ACL: \nswitch(config-dot1x)#show running-config section access-list\nip access-list denyipv4all\n   counters per-entry\n   10 deny ip any any\u2019\n\n\n\nPossible scenarios where traffic can leak:\nACL should be configured with an 802.1X authenticator. Once a supplicant is authenticated and the AAA server sends an ACL filter rule via an ACCESS-ACCEPT message, it takes some time for the ACL to be successfully applied. During this time, between receiving the ACCESS-ACCEPT and the successful application of the ACL, traffic may leak.\n\nACL should be configured with an 802.1X authenticator. Hardware TCAM space should get exhausted by adding more number of ACL\u2019s on the hardware, once supplicant is authenticated and the AAA server sends an ACL filter rule via an ACCESS-ACCEPT message, it takes time to apply ACL, in this case it will fail to apply due to space not being available. During the time between receiving the ACCESS-ACCEPT and the ACL application failure due to space not available, traffic may leak.\n",
          "title": "1108416: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-77191"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.8",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.6",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.1",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "There is no work around for this issue which can avoid the behavior."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.6,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-1",
            "CSAFPID-2",
            "CSAFPID-3"
          ]
        }
      ],
      "title": "CVE-2026-77191"
    },
    {
      "cve": "CVE-2026-75943",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1302705"
      },
      "notes": [
        {
          "category": "description",
          "text": "A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the \"clear dot1x host all\" CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to any of the vulnerabilities, the following condition must be met under interface configuration mode:\n\n1. 802.1X (dot1x in the CLI) must be configured with `pae authenticator`\n2. port-control must be set to auto mode\n3. A static or dynamic ACL must be configured.\n4. The RADIUS Access-Accept or Change-of-Authorization (CoA) assigns an ACL to that supplicant using RADIUS AVP (Attribute-Value pair) Filter-Id or NAS-Filter-Rule\n\nBelow is an example of one configuration. Note that \u201cmac based authentication always\u201d is optional The supplicant can authenticate with either EAPOL or MBA.\n\nIn this example port control is in \u201cauto\u201d mode, necessary for the condition to occur.\n\nUse a preconfigured ACL with which the RADIUS server returns in the `Filter-Id` AVP\n\nAAA server will return the ACL name through `Filter-Id` AVP through Access-Accept or CoA messages , in the above sample , Filter-Id AVP with EMPLOYEE-ACL will be received from the server`.`\n\nTo verify the configured ACL, execute the following show command to identify the ACL applied to the interface:\n\n#### CVE-2026-75945\n\nIn addition to the prerequisite above to configure 802.1X in authenticator mode with ACL-based authorization, the supplicant(s) must be removed via the below command:",
          "title": "1302705: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-4",
          "CSAFPID-5",
          "CSAFPID-6",
          "CSAFPID-7"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75943"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-7"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.6,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-3",
            "CSAFPID-6",
            "CSAFPID-7",
            "CSAFPID-4",
            "CSAFPID-5"
          ]
        }
      ],
      "title": "CVE-2026-75943"
    },
    {
      "cve": "CVE-2026-75944",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1697612"
      },
      "notes": [
        {
          "category": "description",
          "text": "A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to any of the vulnerabilities, the following condition must be met under interface configuration mode:\n\n1. 802.1X (dot1x in the CLI) must be configured with `pae authenticator`\n2. port-control must be set to auto mode\n3. A static or dynamic ACL must be configured.\n4. The RADIUS Access-Accept or Change-of-Authorization (CoA) assigns an ACL to that supplicant using RADIUS AVP (Attribute-Value pair) Filter-Id or NAS-Filter-Rule\n\nBelow is an example of one configuration. Note that \u201cmac based authentication always\u201d is optional The supplicant can authenticate with either EAPOL or MBA.\n\nIn this example port control is in \u201cauto\u201d mode, necessary for the condition to occur.\n\nUse a preconfigured ACL with which the RADIUS server returns in the `Filter-Id` AVP\n\nAAA server will return the ACL name through `Filter-Id` AVP through Access-Accept or CoA messages , in the above sample , Filter-Id AVP with EMPLOYEE-ACL will be received from the server`.`\n\nTo verify the configured ACL, execute the following show command to identify the ACL applied to the interface:\n\n#### CVE-2026-75945\n\nIn addition to the prerequisite above to configure 802.1X in authenticator mode with ACL-based authorization, the supplicant(s) must be removed via the below command:",
          "title": "1697612: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-8"
        ],
        "fixed": [
          "CSAFPID-4",
          "CSAFPID-5",
          "CSAFPID-6",
          "CSAFPID-7"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75944"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-7"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-8"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-6",
            "CSAFPID-8",
            "CSAFPID-7",
            "CSAFPID-4",
            "CSAFPID-5"
          ]
        }
      ],
      "title": "CVE-2026-75944"
    },
    {
      "cve": "CVE-2026-75945",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1857804"
      },
      "notes": [
        {
          "category": "description",
          "text": "A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to any of the vulnerabilities, the following condition must be met under interface configuration mode:\n\n1. 802.1X (dot1x in the CLI) must be configured with `pae authenticator`\n2. port-control must be set to auto mode\n3. A static or dynamic ACL must be configured.\n4. The RADIUS Access-Accept or Change-of-Authorization (CoA) assigns an ACL to that supplicant using RADIUS AVP (Attribute-Value pair) Filter-Id or NAS-Filter-Rule\n\nBelow is an example of one configuration. Note that \u201cmac based authentication always\u201d is optional The supplicant can authenticate with either EAPOL or MBA.\n\nIn this example port control is in \u201cauto\u201d mode, necessary for the condition to occur.\n\nUse a preconfigured ACL with which the RADIUS server returns in the `Filter-Id` AVP\n\nAAA server will return the ACL name through `Filter-Id` AVP through Access-Accept or CoA messages , in the above sample , Filter-Id AVP with EMPLOYEE-ACL will be received from the server`.`\n\nTo verify the configured ACL, execute the following show command to identify the ACL applied to the interface:\n\n#### CVE-2026-75945\n\nIn addition to the prerequisite above to configure 802.1X in authenticator mode with ACL-based authorization, the supplicant(s) must be removed via the below command:",
          "title": "1857804: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-8"
        ],
        "fixed": [
          "CSAFPID-4",
          "CSAFPID-5",
          "CSAFPID-6",
          "CSAFPID-7"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-75945"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-7"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-8"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.6,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-6",
            "CSAFPID-8",
            "CSAFPID-7",
            "CSAFPID-4",
            "CSAFPID-5"
          ]
        }
      ],
      "title": "CVE-2026-75945"
    }
  ]
}