CVE-2024-27892
CRITICALArista EOS OpenConfig with SSL Profiles - gNMI Set Authentication Bypass
Title source: manualDescription
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
References (1)
Core 1
Scores
CVSS v3
9.6
EPSS
0.0030
EPSS Percentile
21.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (8)
Arista Networks/EOS
4.24.0 - 4.24.11M
Arista Networks/EOS
4.25.0 - 4.25.10M
Arista Networks/EOS
4.26.0 - 4.26.9M
Arista Networks/EOS
4.27.0 - 4.27.8M
Arista Networks/EOS
4.28.0 - 4.28.10M
Arista Networks/EOS
4.29.0 - 4.29.7M
Arista Networks/EOS
4.30.0 - 4.30.5M
Arista Networks/EOS
4.31.0 - 4.31.2F
Published
Jun 04, 2026
Tracked Since
Jun 05, 2026