CVE-2023-5502: Arista Networks Eos

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.

Affected products

  • Arista Networks Eos: from 4.31.0, up to and including 4.31.0F; from 4.30.0, up to and including 4.30.4M; from 4.29.0, up to and including 4.29.6M; from 4.28.0, up to and including 4.28.8M; from 4.27.0, up to and including 4.27.11M; from 4.26.0, up to and including 4.26.11M; …

Published 2026-06-04. Last modified 2026-07-22.