🔐 CVE Alert

CVE-2023-5502

MEDIUM 5.9

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
9th

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.

CWE CWE-287
Vendor arista networks
Product eos
Published Jun 4, 2026
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for arista networks eos

Be the first to know when new medium vulnerabilities affecting arista networks eos are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Arista Networks / EOS
4.31.0 ≤ 4.31.0F 4.30.0 ≤ 4.30.4M 4.29.0 ≤ 4.29.6M 4.28.0 ≤ 4.28.8M 4.27.0 ≤ 4.27.11M 4.26.0 ≤ 4.26.11M 4.25.0 ≤ 4.25.11M 4.24.0 ≤ 4.24.11M

References

NVD ↗ CVE.org ↗ EPSS Data ↗
arista.com: https://www.arista.com/en/support/advisories-notices/security-advisory/19462-security-advisory-0096