Authentication Bypass Vulnerability in Arista EOS Switches
CVE-2024-6858

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2024-6858?

In Arista's EOS operating system, when configured in 802.1X mode, an authentication bypass issue exists where unauthenticated hosts may gain unauthorized access to a switch port. This vulnerability arises when there is an EAPOL-capable device present in the fallback VLAN, potentially compromising the network's security. Organizations should review their EOS configurations to mitigate the risk associated with this vulnerability.

Affected Version(s)

EOS 720D Series 4.31.0 <= 4.31.1F

EOS 720D Series 4.30.0 <= 4.30.5M

EOS 720D Series 4.29.0 <= 4.29.7M

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.