Security features bypass in Arista Extensible Operating System (EOS) - CVE-2024-27891
Published: May 17, 2025
Vulnerability identifier: #VU109369
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27891
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error on Arista EOS with MACsec and egress ACLs configured on the same interfaces. The ACL policies may not be enforced for packets egressing on those ports.
Affected software
Arista Extensible Operating System (EOS)
How to mitigate CVE-2024-27891
Install updates from vendor's website.
Arista Extensible Operating System (EOS) - addressed in versions 4.28.11M, 4.29.8M, 4.30.7M, 4.31.3M, 4.32.1F