CVE-2026-75945: CWE-459 Incomplete Cleanup in Arista Networks EOS
CVE-2026-75945 is a low-severity vulnerability in Arista Networks EOS where a race condition can cause a supplicant to remain authorized after issuing the 'clear dot1x host all' command. This incomplete cleanup issue may allow continued access despite the command intended to clear authorization states.
AI Analysis
Technical Summary
This vulnerability involves a race condition in Arista Networks EOS versions 4.36.0 through 4.36.1F. When the 'clear dot1x host all' command is executed, a supplicant may remain in an authorized state due to incomplete cleanup of authorization information. The CVSS 3.1 base score is 2.6, indicating low severity, with low impact on integrity and no impact on confidentiality or availability. The attack vector is adjacent network, requiring high attack complexity and low privileges, with no user interaction needed.
Potential Impact
The impact is limited to a potential integrity issue where a supplicant remains authorized after a command intended to clear authorization states. There is no impact on confidentiality or availability. This could allow continued network access by a device that should have been deauthorized, but exploitation requires specific conditions and is of low severity.
Mitigation Recommendations
No vendor advisory or patch information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should be aware of the potential for incomplete cleanup when using the 'clear dot1x host all' command and consider operational controls accordingly.
CVE-2026-75945: CWE-459 Incomplete Cleanup in Arista Networks EOS
Description
CVE-2026-75945 is a low-severity vulnerability in Arista Networks EOS where a race condition can cause a supplicant to remain authorized after issuing the 'clear dot1x host all' command. This incomplete cleanup issue may allow continued access despite the command intended to clear authorization states.
CVSS v3.1
Score 2.6low
Affected software
Arista Networks
EOS
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a race condition in Arista Networks EOS versions 4.36.0 through 4.36.1F. When the 'clear dot1x host all' command is executed, a supplicant may remain in an authorized state due to incomplete cleanup of authorization information. The CVSS 3.1 base score is 2.6, indicating low severity, with low impact on integrity and no impact on confidentiality or availability. The attack vector is adjacent network, requiring high attack complexity and low privileges, with no user interaction needed.
Potential Impact
The impact is limited to a potential integrity issue where a supplicant remains authorized after a command intended to clear authorization states. There is no impact on confidentiality or availability. This could allow continued network access by a device that should have been deauthorized, but exploitation requires specific conditions and is of low severity.
Mitigation Recommendations
No vendor advisory or patch information is provided. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should be aware of the potential for incomplete cleanup when using the 'clear dot1x host all' command and consider operational controls accordingly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Arista
- Date Reserved
- 2026-08-18T16:04:12.507Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa883f355bf5e2cf5cca438
Added to database: 09/14/2026, 23:32:03 UTC
Last enriched: 09/14/2026, 23:46:26 UTC
Last updated: 09/15/2026, 00:21:31 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.