Configuration Management Vulnerability in Arista EOS
CVE-2024-27892

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2024-27892?

A critical flaw in Arista EOS affects installations where OpenConfig is enabled. The vulnerability allows unauthorized gNMI Set requests to be processed, even when they should be rejected. This can lead to unexpected and potentially harmful configurations being applied to network switches, compromising the integrity and security of network operations. Network administrators should review their configurations and apply necessary mitigations to prevent unauthorized access.

Affected Version(s)

EOS 710 Series 4.31.0 <= 4.31.2F

EOS 710 Series 4.30.0 <= 4.30.5M

EOS 710 Series 4.29.0 <= 4.29.7M

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.