Configuration Management Vulnerability in Arista EOS
CVE-2024-27892
7.2HIGH
What is CVE-2024-27892?
A critical flaw in Arista EOS affects installations where OpenConfig is enabled. The vulnerability allows unauthorized gNMI Set requests to be processed, even when they should be rejected. This can lead to unexpected and potentially harmful configurations being applied to network switches, compromising the integrity and security of network operations. Network administrators should review their configurations and apply necessary mitigations to prevent unauthorized access.
Affected Version(s)
EOS 710 Series 4.31.0 <= 4.31.2F
EOS 710 Series 4.30.0 <= 4.30.5M
EOS 710 Series 4.29.0 <= 4.29.7M
