CVE-2026-73458
- EPSS 0.38%
- Veröffentlicht 15.09.2026 19:30:16
- Zuletzt bearbeitet 16.09.2026 19:08:50
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because vario...
CVE-2026-73467
- EPSS 0.09%
- Veröffentlicht 15.09.2026 18:44:39
- Zuletzt bearbeitet 16.09.2026 19:09:28
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
CVE-2026-73466
- EPSS 0.09%
- Veröffentlicht 15.09.2026 18:41:04
- Zuletzt bearbeitet 17.09.2026 12:18:26
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabi...
CVE-2026-73465
- EPSS 0.09%
- Veröffentlicht 15.09.2026 18:36:51
- Zuletzt bearbeitet 17.09.2026 12:18:26
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vu...
CVE-2026-19641
- EPSS 0.34%
- Veröffentlicht 15.09.2026 18:17:55
- Zuletzt bearbeitet 16.09.2026 19:08:50
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in...
CVE-2026-73451
- EPSS 0.18%
- Veröffentlicht 15.09.2026 18:12:44
- Zuletzt bearbeitet 16.09.2026 19:08:50
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcar...
CVE-2026-75945
- EPSS 0.13%
- Veröffentlicht 14.09.2026 22:23:02
- Zuletzt bearbeitet 16.09.2026 20:36:52
A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
CVE-2026-75944
- EPSS 0.15%
- Veröffentlicht 14.09.2026 22:19:19
- Zuletzt bearbeitet 16.09.2026 20:36:52
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement...
CVE-2026-75943
- EPSS 0.13%
- Veröffentlicht 14.09.2026 22:11:53
- Zuletzt bearbeitet 16.09.2026 20:36:52
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL en...
CVE-2026-77191
- EPSS 0.14%
- Veröffentlicht 14.09.2026 22:06:28
- Zuletzt bearbeitet 16.09.2026 20:36:52
An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcem...