CVE-2026-73449
Received Received - Intake

Denial of Service in Arista EOS RADIUS Proxy

Vulnerability report for CVE-2026-73449, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions. This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network. Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista arista_eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices with both 802.1X port authentication and RADIUS proxy with dynamic authorization enabled. A low-privileged attacker on an adjacent network segment can send a RADIUS packet through a configured proxy client to block dynamic authorization messages like Change-of-Authorization or Disconnect-Requests. This prevents the network from disconnecting endpoints that should have been removed.

Detection Guidance

Detection requires verifying if both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization are configured on Arista EOS devices. Check device configurations for these features and monitor RADIUS traffic for dynamic authorization messages.

Impact Analysis

If exploited, unauthorized endpoints may remain connected to your network even after being ordered to disconnect by a RADIUS server or access control system. This could allow continued access to network resources for devices that should have been removed.

Compliance Impact

This vulnerability could potentially impact compliance with standards like GDPR and HIPAA by allowing unauthorized network access to persist. If a session that should be disconnected remains active due to the RADIUS dynamic authorization failure, it may violate access control policies required by these regulations.

Mitigation Strategies

Disable the RADIUS proxy feature with dynamic authorization if not required. Review and remove any 802.1X port authentication configurations that use dynamic authorization. Monitor network sessions for unauthorized persistence after RADIUS disconnect commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73449. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart