Arista Networks EOS 802.1X Per-Supplicant ACL Bypass (SA0150) (CVE-2026-75943)

low Nessus Plugin ID 346258

Synopsis

The version of Arista Networks EOS running on the remote device is affected by an access control bypass vulnerability.

Description

The version of Arista Networks EOS running on the remote device is affected by an access control bypass vulnerability as referenced in security advisory SA0150.

- On affected releases of Arista EOS configured as an 802.1X authenticator with per-supplicant access control lists, traffic from an authenticated supplicant may bypass the access control list assigned to that supplicant, allowing an adjacent attacker to send traffic that should have been denied. (CVE-2026-75943)

Note that Nessus has not checked the 802.1X authenticator and per-supplicant ACL configuration required for exposure and has instead relied only on the application's self-reported version number.

Solution

Upgrade to Arista Networks EOS 4.33.10M / 4.34.8M / 4.35.6M / 4.36.2F or later, or apply the mitigation referenced in the vendor advisory.

See Also

http://www.nessus.org/u?4f5cda50

Plugin Details

Severity: Low

ID: 346258

File Name: arista_eos_cve-2026-75943.nasl

Version: 1.2

Type: Combined

Family: Misc.

Published: 9/16/2026

Updated: 9/17/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 1.4

Temporal Score: 1

Vector: CVSS2#AV:A/AC:H/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2026-75943

CVSS v3

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2.3

Vector: CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2.1

Threat Score: 0.5

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:arista:eos

Required KB Items: Settings/ParanoidReport, Host/Arista-EOS/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 9/9/2026

Vulnerability Publication Date: 9/9/2026

Reference Information

CVE: CVE-2026-75943