On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.
| Vendor | Product | Versions |
|---|---|---|
| arista | eos | 4.31.0, 4.30.0, 4.29.0, 4.28.0, 4.27.0, 4.26.0, 4.25.0, 4.24.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| arista | eos | cert_advisory | 90% |
Updated severity to CRITICAL, marked as actively exploited, and specified patch available as version 4.31.0F.
Initial creation