Skip to content

Security Advisory Tests

This page documents each security advisory test currently implemented in ANTA. See the Security Advisory Tests Overview for the support matrix.

SA178

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0178.

Expected Results
  • Success: The test will pass if no SNMPv3 authentication key is configured, or every key uses encrypted syntax.
  • Failure: The test will fail if an SNMPv3 authentication key uses legacy or mixed syntax. Affected software requires an upgrade followed by credential conversion; fixed software requires credential conversion because upgrading does not rewrite existing configuration.
  • Error: The test will error if the required EOS version, authentication-key state, or credential syntax cannot be determined.

Security advisory: Security Advisory 0178

SA177

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0177.

The advisory describes the exposure as requiring active MLAG. This test deliberately uses the complete persistent MLAG configuration instead: a configured domain ID, local interface, peer address, and peer link are treated as exposed regardless of the currently reported operational state. An inactive peer or domain can become active immediately after evidence collection, so transient inactivity does not establish that the device is not affected.

Expected Results
  • Success: EOS or the platform is outside scope, PIM Sparse Mode is absent, or the complete MLAG configuration is absent.
  • Failure: An affected EOS release and platform have both PIM Sparse Mode and the complete MLAG configuration.
  • Error: Required EOS, platform, PIM Sparse Mode, or MLAG configuration cannot be determined.

Security advisory: Security Advisory 0177

SA176

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0176.

Expected Results
  • Success: The test passes when EOS or the platform is outside scope, or loose uRPF is not configured.
  • Failure: The test fails when an affected EOS release and platform have loose IPv4 or IPv6 uRPF configured.
  • Error: The test errors when required EOS, platform, loose-uRPF, or any needed switch-card state cannot be determined.

Security advisory: Security Advisory 0176

SA175

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0175.

Expected Results
  • Success: The test passes when the EOS version is outside scope or no PIM sparse-mode interface is configured.
  • Failure: The test fails when an affected EOS version has an IPv4 or IPv6 PIM sparse-mode interface.
  • Error: The test errors when required EOS version or PIM sparse-mode state cannot be determined.

Security advisory: Security Advisory 0175

SA174

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0174.

Expected Results
  • Success: EOS is outside scope, P4Runtime is disabled, or mTLS is used without request accounting or gNSI Acctz.
  • Failure: P4Runtime lacks mTLS, or accounting is active while gNSI Authz is disabled or unsupported.
  • Inconclusive: Accounting and gNSI Authz are enabled, but the installed Authz policy cannot be verified.
  • Error: Required EOS, P4Runtime, TLS, accounting, or gNSI Authz state cannot be determined.

Security advisory: Security Advisory 0174

SA173

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0173.

Expected Results
  • Success: The test will pass if the EOS version is outside scope or both supported observations prove OSPFv3 is absent.
  • Failure: The test will fail if affected EOS has OSPFv3 configured without complete IPsec coverage or an applicable hotfix.
  • Mitigated: The test is mitigated when IPsec covers every configured OSPFv3 scope or an applicable persistent hotfix is installed.
  • Error: The test will error if required EOS version, OSPFv3 configuration, IPsec coverage, or applicable hotfix state cannot be determined.

Active-neighbor absence is not accepted as a safe state because adjacency state is transient. IPsec mitigation is evaluated against persistent interface, VRF, area, and address-family configuration instead of the neighbors present when the test runs.

Security advisory: Security Advisory 0173

SA172

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0172.

Expected Results
  • Success: EOS is outside scope or both supported observations prove OSPFv3 is absent.
  • Failure: An affected EOS release has OSPFv3 configured without complete IPsec authentication coverage.
  • Mitigated: IPsec authentication covers every configured OSPFv3 interface scope on an affected release.
  • Error: Required EOS, OSPFv3 configuration, or IPsec authentication state cannot be determined.

Security advisory: Security Advisory 0172

SA171

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0171.

Expected Results
  • Success: An issue’s EOS version is outside scope; or, for CVE-2026-73435, no OSPFv2 process is configured; or, for CVE-2026-73436, OSPF segment routing is not enabled.
  • Failure: On an affected EOS release, an active OSPFv2 broadcast interface reports cryptographic authentication for CVE-2026-73435, or OSPF segment routing is enabled for CVE-2026-73436.
  • Mitigated: For CVE-2026-73435, the SWIX is installed and boot-persistent on an explicitly supported release. This is decisive even when no qualifying broadcast interface is currently active.
  • Inconclusive: For CVE-2026-73435, an affected EOS release has an OSPFv2 process configured, but no active broadcast interface reporting cryptographic authentication is currently observable.
  • Error: Required EOS, OSPFv2, or applicable SWIX state cannot be determined.

The two vulnerabilities have independent version boundaries and prerequisites. In particular, 4.34.7.1M fixes CVE-2026-73435 but remains affected by CVE-2026-73436.

CVE-2026-73435 follows this decision pattern:

  • An active OSPFv2 broadcast interface reporting cryptographic authentication confirms an affected condition, regardless of its current neighbor count.
  • No configured OSPFv2 process closes the exposure path and produces a not-affected result.
  • A configured OSPFv2 process without a currently observable qualifying active interface is inconclusive. Interface state can change without an OSPF configuration change, and authentication may be inherited from area, process, or interface configuration.
  • An applicable effective SWIX resolves that uncertainty and produces a mitigated result.

The test deliberately does not reconstruct effective OSPF behavior from static network, passive-interface, or authentication configuration. Process configuration is used only to distinguish an absent exposure path from an unresolved inactive one.

Security advisory: Security Advisory 0171

SA170

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0170.

Expected Results
  • Success: EOS is outside scope or no enabled gNMI transport uses request authorization.
  • Failure: An affected EOS release has an enabled gNMI transport using request authorization.
  • Error: Required EOS or gNMI authorization state cannot be determined.

Security advisory: Security Advisory 0170

SA169

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0169.

Expected Results
  • Success: EOS is outside scope, gNSI has no enabled transport, or Authz is disabled.
  • Failure: Affected EOS has gNSI Authz and multiple transports enabled.
  • Inconclusive: Affected EOS has gNSI Authz and one transport enabled, but a removed secondary transport may have left stale policy state.
  • Error: Required EOS or gNSI state cannot be determined.

Security advisory: Security Advisory 0169

SA168

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0168.

Expected Results
  • Success: EOS is outside scope or gNMI, RESTCONF, and NETCONF are all disabled or unsupported.
  • Failure: An affected EOS release has at least one of those OpenConfig services enabled.
  • Error: No service proves exposure and required EOS or service state cannot be determined.

Security advisory: Security Advisory 0168

SA167

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0167.

Expected Results
  • Success: The test will pass if the EOS version is outside the affected releases, no gNSI transport is enabled, or Authz is disabled.
  • Failure: The test will fail if affected EOS has an enabled gNSI transport and Authz service.
  • Error: The test will error if required EOS version, transport, or Authz state cannot be determined.

Security advisory: Security Advisory 0167

SA166

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0166.

Expected Results
  • Success: EOS is outside scope or no gNMI transport is enabled.
  • Failure: An affected EOS release has an enabled gNMI transport.
  • Error: Required EOS or gNMI state cannot be determined.

Security advisory: Security Advisory 0166

SA165

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0165.

Expected Results
  • Success: EOS is outside scope or gNSI Credentialz is disabled or unsupported.
  • Failure: An affected EOS release has gNSI Credentialz enabled.
  • Error: Required EOS or Credentialz state cannot be determined.

Security advisory: Security Advisory 0165

SA164

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0164.

Expected Results
  • Success: The test will pass if EOS is outside scope, gNMI or Pathz is disabled, or the Pathz policy has no user/group path overlap.
  • Failure: The test will fail if affected EOS has gNMI and Pathz enabled with user and group rules for the same path.
  • Error: The test will error if required EOS, gNMI, Pathz, or persisted policy state cannot be determined.

Security advisory: Security Advisory 0164

SA163

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0163.

Expected Results
  • Success: EOS is outside scope or no enabled gNMI transport combines mutual TLS with request authorization.
  • Failure: An affected release has an exposed transport without the documented AAA mitigation.
  • Mitigated: The exposed transport is covered by explicit privilege-level-zero AAA authorization.
  • Error: Required EOS, transport, SSL-profile, or AAA state cannot be determined.

Security advisory: Security Advisory 0163

SA162

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0162.

Expected Results
  • Success: The test will pass if the EOS version is outside the affected releases.
  • Failure: The test will fail if an affected EOS version has an enabled gNSI transport and Certz service.
  • Inconclusive: The test is inconclusive when the Certz path is closed but Bootz certificate use during initial provisioning is unknown.
  • Error: The test will error if EOS or current Certz-path state needed for the assessment cannot be determined.

Security advisory: Security Advisory 0162

SA161

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0161.

Expected Results
  • Success: EOS is outside scope or the local vulnerable MLAG dual-primary configuration is absent.
  • Failure: An affected EOS release has MLAG dual-primary heartbeat configured with the errdisable-all action.
  • Error: Required EOS or local MLAG state cannot be determined.

Transient MLAG, peer-link, heartbeat, and dual-primary operational states do not remove exposure from a device with the vulnerable configuration.

Security advisory: Security Advisory 0161

SA160

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0160.

Expected Results
  • Success: An issue’s EOS version is outside scope; no IS-IS instance is enabled; or the issue-specific prerequisite is absent.
  • Failure: An affected EOS release reports the issue-specific IS-IS prerequisite.
  • Inconclusive: For CVE-2026-73446, an affected EOS release has IS-IS enabled, but no qualifying active interface is currently observable.
  • Error: Required EOS or IS-IS state cannot be determined.

Each vulnerability has an independent version matrix and prerequisite: a reported non-passive broadcast interface, any enabled IS-IS instance, or graceful restart.

A reported non-passive broadcast interface confirms CVE-2026-73446 exposure regardless of its current adjacency count. When IS-IS is enabled but no qualifying interface is reported, the result is inconclusive because a configured interface may be temporarily down and omitted from operational output. The test deliberately does not reconstruct effective interface type, passive state, or shutdown behavior from static EOS configuration.

Security advisory: Security Advisory 0160

SA159

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0159.

Expected Results
  • Success: EOS is outside the affected releases.
  • Failure: EOS is within the affected releases; IGMP snooping is instantiated by default.
  • Error: The EOS version cannot be determined.

Security advisory: Security Advisory 0159

SA158

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0158.

Expected Results
  • Success: EOS is outside scope, gNPSI is disabled, or the issue-specific authentication or trace prerequisite is absent.
  • Failure: An affected EOS release has an enabled gNPSI transport and the issue-specific prerequisite.
  • Mitigated: Credential tracing is enabled, but every enabled transport uses mutual TLS with only x509-spiffe authentication.
  • Error: Required EOS, gNPSI transport, authentication, or trace state cannot be determined.

CVE-2026-73456 evaluates TLS or mTLS authentication combinations. CVE-2026-73457 evaluates explicit EosRpcAuth tracing and the source-defined mutual-TLS/x509-spiffe mitigation across every enabled transport.

Security advisory: Security Advisory 0158

SA157

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0157.

Expected Results
  • Success: EOS is outside scope or the configuration prerequisite for an issue is absent; replay also requires anti-replay after updating.
  • Failure: An affected release has the issue’s VRRP prerequisite, or a conditionally fixed release lacks anti-replay for the replay issue.
  • Error: Required EOS or VRRP state cannot be determined.

Replay protection is disabled by default after updating, so CVE-2026-73443 requires both fixed software and the global anti-replay setting. Assessment uses persistent VRRP configuration rather than transient operational state. CVE-2026-73444 and CVE-2026-73443 require VRRPv2 with IP-AH authentication, while CVE-2026-73442 applies when either VRRPv2 or VRRPv3 is configured.

Security advisory: Security Advisory 0157

SA156

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0156.

Expected Results
  • Success: DHCP relay is inactive, EOS is outside scope, or a conditionally fixed release has reply validation enabled.
  • Failure: Active DHCP relay is neither fully resolved nor covered by operational enforcement-disabled IP locking.
  • Mitigated: Enforcement-disabled IP locking operationally covers every active relay interface and address family.
  • Error: Required EOS, DHCP relay, reply-validation, or IP-locking scope cannot be determined.

A software update alone is insufficient. The advisory requires reply source-address validation on every fixed release. Its alternative IP-locking mitigation is accepted only from operational state whose interface or VLAN and IPv4/IPv6 coverage can be correlated with every active DHCP relay path. Unsupported IP locking proves that mitigation is absent.

Security advisory: Security Advisory 0156

SA155

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0155.

Expected Results
  • Success: EOS is outside scope or none of the DHCP Option 82 exposure paths is configured.
  • Failure: An affected EOS release has a DHCP relay, snooping, or server Option 82 exposure path.
  • Error: Required EOS or DHCP configuration state cannot be determined.

Security advisory: Security Advisory 0155

SA154

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0154.

BFD is exposed when it is enabled and authentication is configured. Active peers are not required because peer state is transient and a configured interface or peer may establish a session after the test runs.

Expected Results
  • Success: EOS is outside scope, BFD is shut down, or BFD authentication is not configured.
  • Failure: An affected EOS release has BFD enabled with authentication configured.
  • Error: Required EOS or BFD state cannot be determined.

Security advisory: Security Advisory 0154

SA153

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0153.

Expected Results
  • Success: Each issue passes when the EOS version is outside its affected scope or its risky trace level is disabled.
  • Failure: An issue fails when an affected EOS release has its risky trace level enabled.
  • Error: An issue errors when required EOS version or trace state cannot be determined.

Security advisory: Security Advisory 0153

SA152

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0152.

Expected Results
  • Success: EOS is outside scope, login authentication is disabled, or no password-capable management service is enabled.
  • Failure: Affected EOS has login authentication and password-capable SSH or Telnet enabled.
  • Error: Required EOS, AAA, or management-service configuration cannot be determined.

SSH and Telnet exposure is determined from configuration, including configured VRF scope. Current VRF operational state is transient and does not prove safety because a down VRF can return without any management-service configuration change.

Security advisory: Security Advisory 0152

SA151

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0151.

Expected Results
  • Success: EOS or platform is outside scope, or no shared SVI ingress ACL is configured.
  • Failure: Affected EOS and platform have a shared SVI ingress ACL configured.
  • Error: Required EOS, platform, or shared SVI ingress ACL state cannot be determined.

Security advisory: Security Advisory 0151

SA150

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0150.

Expected Results
  • Success: An issue passes when EOS or platform is outside its scope, or no controlled 802.1X authenticator is active.
  • Inconclusive: An applicable issue is inconclusive because static or dynamic ACL assignment cannot be ruled out from device state.
  • Error: An issue errors when required EOS, platform, or 802.1X state cannot be determined.

Whether an operator previously ran clear dot1x host all does not change exposure assessment. For CVE-2026-75945, rerunning that command is presented only as conditional mitigation advice when a supplicant remains authenticated.

Security advisory: Security Advisory 0150

SA149

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0149.

Expected Results
  • Success: EOS or platform is outside scope, or either required dynamic-authorization feature is absent.
  • Failure: An affected physical platform and EOS release has both required features configured.
  • Error: Required EOS, platform, 802.1X, or RADIUS proxy state cannot be determined.

Security advisory: Security Advisory 0149

SA147

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0147.

Strict host-key checking is an observable identity control for CVE-2026-60002, but it does not establish that operators connect only to trusted servers as required by the advisory. An affected release with strict host-key checking is therefore inconclusive rather than mitigated.

Expected Results
  • Success: The test will pass if every vulnerability is not affected.
  • Failure: The test will fail if any vulnerability is affected or inconclusive.
  • Error: The test will error if evidence required for a vulnerability is invalid.

Security advisory: Security Advisory 0147

SA146

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0146.

Notes

TerminAttr validates its configured certificate, private key, and client CA files when it starts. A running TerminAttr process configured with the complete mTLS arguments therefore has valid files and enforces mTLS. If file validation prevents TerminAttr from starting, its gRPC service is not exposed. The TerminAttr mTLS path is therefore safely classified as mitigated.

Expected Results
  • Success: The test will pass if no affected gRPC service is enabled.
  • Failure: The test will fail if an affected gRPC service is enabled without mTLS.
  • Mitigated: The test is mitigated if all affected services are protected with mTLS.
  • Error: The test will error if a required service, EOS release, component version, or mTLS state cannot be determined.

Security advisory: Security Advisory 0146

SA142

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0142.

Notes

This test currently requires the structured EOS platform identity supplied by AsyncEOSDevice. Incomplete modular identities remain inconclusive when the installed modules cannot establish the affected family.

Expected Results
  • Success: The test will pass if no affected redirect path is active or a conditional fix is complete.
  • Failure: The test will fail if a vulnerable redirect path is active or a conditional fix is incomplete.
  • Inconclusive: The test is inconclusive for a conservatively matched chassis.
  • Error: The test will error if a required redirect, platform, EOS release, or MTU control state cannot be determined.

Security advisory: Security Advisory 0142

SA140

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0140.

Expected Results
  • Success: The test will pass if the EOS version or Secure Boot state is not affected.
  • Failure: The test will fail if an affected EOS version has Secure Boot supported and enabled.
  • Error: The test will error if the EOS version or Secure Boot state cannot be determined.

Security advisory: Security Advisory 0140

SA117

Preview badge

Preview

Input models and behavior may change between minor releases without a deprecation notice.

Verify whether the device is impacted by Security Advisory 0117.

Notes

Exposure signals remain inconclusive because disabling the gNOI File service and an effective gNSI Authz policy that blocks TransferToRemote cannot currently be evaluated with trusted narrow EOS evidence.

Expected Results
  • Success: The test will pass if the EOS version or configuration is not affected.
  • Inconclusive: The test is inconclusive if exposure signals exist but required control evidence is unavailable.
  • Error: The test will error if required EOS version or configuration evidence is invalid.

Security advisory: Security Advisory 0117