Security features bypass in Arista Extensible Operating System (EOS) - CVE-2024-27891

 

Security features bypass in Arista Extensible Operating System (EOS) - CVE-2024-27891

Published: May 17, 2025


Vulnerability identifier: #VU109369
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27891
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an unspecified error on Arista EOS with MACsec and egress ACLs configured on the same interfaces. The ACL policies may not be enforced for packets egressing on those ports.


Affected software

Arista Extensible Operating System (EOS)

How to mitigate CVE-2024-27891

Install updates from vendor's website.

Arista Extensible Operating System (EOS) - addressed in versions 4.28.11M, 4.29.8M, 4.30.7M, 4.31.3M, 4.32.1F

External References

Related Security Bulletins