Back

HIGH

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.

Published Jun 4, 2026

Description

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.

Affected products

Remediation

Vendor solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades https://www.arista.com/en/um-eos/eos-upgrades-and-downgrades

CVE-2023-5502 has been fixed in the following releases: * 4.32.0F and later releases in the 4.32.x train * 4.31.3M and later releases in the 4.31.x train * 4.30.5M and later releases in the 4.30.x train * 4.29.7M and later releases in the 4.29.x train

Note: Products 7280E and 7500E are EOL, and there are no released versions of EOS which fix the issue on those platforms.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Arista
Published Jun 4, 2026
Updated Jun 5, 2026
Reserved Oct 10, 2023
CISA Vulnrichment
Updated Jun 5, 2026
NVD
Status Awaiting Analysis
Modified Jul 22, 2026
Red Hat
Severity n/a
Public date n/a