On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.
CVE-2024-27891

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2024-27891?

On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.

Affected Version(s)

EOS 722XPM Series 4.32.0 <= 4.32.0.1F

EOS 722XPM Series 4.31.0 <= 4.31.2F

EOS 722XPM Series 4.30.0 <= 4.30.6M

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.