Egress Packet Control Flaw in Arista EOS Leading to Enforcement Issues
CVE-2024-27891

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2024-27891?

In configurations where Arista EOS integrates both MACsec and egress ACLs on the same interfaces, a vulnerability exists that may prevent the proper enforcement of ACL policies. This could result in improper allowance or denial of outgoing packets. As a result, the integrity and security of the network may be compromised, enabling potential unauthorized data transmission.

Affected Version(s)

EOS 722XPM Series 4.32.0 <= 4.32.0.1F

EOS 722XPM Series 4.31.0 <= 4.31.2F

EOS 722XPM Series 4.30.0 <= 4.30.6M

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.