Arista Networks EOS 4.36.1F Multiple Vulnerabilities (SA0150)

medium Nessus Plugin ID 346256

Synopsis

The version of Arista Networks EOS running on the remote device is affected by multiple vulnerabilities.

Description

The version of Arista Networks EOS running on the remote device is affected by multiple vulnerabilities as referenced in security advisory SA0150.

- On Arista EOS 4.36.1F configured as an 802.1X authenticator with per-supplicant access control lists, an adjacent attacker can trigger an unexpected condition that results in a denial of service on the affected device. (CVE-2026-75944)

- On Arista EOS 4.36.1F configured as an 802.1X authenticator with per-supplicant access control lists, the access control list assigned to an authenticated supplicant may not be enforced as intended, allowing an adjacent attacker to send traffic that should have been denied. (CVE-2026-75945)

Note that Nessus has not checked the 802.1X authenticator and per-supplicant ACL configuration required for exposure and has instead relied only on the application's self-reported version number.

Solution

Upgrade to Arista Networks EOS 4.36.2F or later, or apply the mitigation referenced in the vendor advisory.

See Also

http://www.nessus.org/u?4f5cda50

Plugin Details

Severity: Medium

ID: 346256

File Name: arista_eos_sa0150.nasl

Version: 1.2

Type: Combined

Family: Misc.

Published: 9/16/2026

Updated: 9/17/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 1.4

Temporal Score: 1

Vector: CVSS2#AV:A/AC:H/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2026-75945

CVSS v3

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2.3

Vector: CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.6

Threat Score: 1.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

CVSS Score Source: CVE-2026-75944

Vulnerability Information

CPE: cpe:/o:arista:eos

Required KB Items: Settings/ParanoidReport, Host/Arista-EOS/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 9/9/2026

Vulnerability Publication Date: 9/9/2026

Reference Information

CVE: CVE-2026-75944, CVE-2026-75945