Race Condition Vulnerability in Arista Networks Products
CVE-2026-75945

2.1LOW

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-75945?

A race condition vulnerability exists in Arista Networks products that may allow a supplicant to retain an authorized state erroneously, even after the issuance of a clear dot1x host all command. This condition may lead to potential security risks, as the system may not accurately reflect the intended authorization state of connected devices. It is crucial for users of affected Arista products to evaluate their security posture and mitigate potential exploitation.

Affected Version(s)

EOS 4.36.0 <= 4.36.1F

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Those issues were discovered internally by Arista, and the company is not aware of any malicious exploitation of these vulnerabilities in customer networks.
.