Race Condition Vulnerability in Arista Access Control System
CVE-2026-75944
5.6MEDIUM
What is CVE-2026-75944?
A race condition has been identified within Arista's Access Control System during the re-authentication process of supplicants. This flaw can lead to the presence of a stale Access Control List (ACL) entry, which may persist across system restarts. If an AclAgent is restarted by an administrator, this outdated entry could then be incorrectly applied to new supplicants, thereby compromising the intended access control measures. This issue emphasizes the importance of proper management and monitoring of access control systems to prevent unauthorized access.
Affected Version(s)
EOS 4.36.0 <= 4.36.1F
References
CVSS V4
Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Those issues were discovered internally by Arista, and the company is not aware of any malicious exploitation of these vulnerabilities in customer networks.
