---
id: CVE-2026-73449
title: >-
  On affected platforms running Arista EOS with both 802.1X port authentication
  and the RADIUS proxy feature configured with dynamic authorization, a
  low-privileged attacker on an adjacent network segment who induces a RADIUS
  packet throug…
summary: >-
  On affected platforms running Arista EOS with both 802.1X port authentication
  and the RADIUS proxy feature configured with dynamic authorization, a
  low-privileged attacker on an adjacent network segment who induces a RADIUS
  packet throug…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L'
cwe:
  - CWE-290
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0 <= 4.36.1F
  - EOS >= 4.35.0 <= 4.35.5M
  - EOS >= 4.34.0 <= 4.34.7.1M
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:08:50.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73449'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24705-security-advisory-0149
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
epss: 0.00145
epssPercentile: 0.04187
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T19:11:42.553584Z'
ingestedAt: '2026-09-14T22:16:09.894Z'
---

## Overview

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions.
This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network.
Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
