CVE-2024-27890

CRITICAL

Arista EOS OpenConfig without SSL Profiles - gNMI Set Authentication Bypass

Title source: manual
STIX 2.1

Description

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

Scores

CVSS v3 9.6
EPSS 0.0443
EPSS Percentile 90.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (6)
Arista Networks/EOS 4.24.0 - 4.24.11M
Arista Networks/EOS 4.25.0 - 4.25.10M
Arista Networks/EOS 4.26.0 - 4.26.9M
Arista Networks/EOS 4.27.0 - 4.27.8M
Arista Networks/EOS 4.28.0 - 4.28.10M
Arista Networks/EOS 4.29.0 - 4.29.7M
Published Jun 04, 2026
Tracked Since Jun 05, 2026