Authentication Bypass Vulnerability in Arista EOS Switches
CVE-2024-6858
6.5MEDIUM
What is CVE-2024-6858?
In Arista's EOS operating system, when configured in 802.1X mode, an authentication bypass issue exists where unauthenticated hosts may gain unauthorized access to a switch port. This vulnerability arises when there is an EAPOL-capable device present in the fallback VLAN, potentially compromising the network's security. Organizations should review their EOS configurations to mitigate the risk associated with this vulnerability.
Affected Version(s)
EOS 720D Series 4.31.0 <= 4.31.1F
EOS 720D Series 4.30.0 <= 4.30.5M
EOS 720D Series 4.29.0 <= 4.29.7M
