Dynamic ACL Installation Issue in Arista EOS with 802.1X Configuration
CVE-2024-8000
5.3MEDIUM
What is CVE-2024-8000?
In Arista EOS platforms configured with 802.1X, a vulnerability exists that affects the installation of dynamic Access Control Lists (ACLs) sourced from the AAA server. After an Accelerated Software Upgrade (ASU) restart, only the first line of the received ACL may be installed. This issue particularly impacts supplicants that have pending captive-portal authentication during the ASU process, posing a risk to correct network access control and security enforcement.
Affected Version(s)
EOS 4.32.0 <= 4.32.4M
EOS 4.31.0 <= 4.31.5M
EOS 4.30.0 <= 4.30.8M