CVE-2024-6858
MEDIUMArista EOS 802.1X Multi-Auth - Authentication Bypass
Title source: manualDescription
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
References (1)
Core 1
Scores
CVSS v3
6.5
EPSS
0.0014
EPSS Percentile
3.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1287
Status
published
Products (4)
Arista Networks/EOS
4.28.10 - 4.28.10.1M
Arista Networks/EOS
4.29.0 - 4.29.7M
Arista Networks/EOS
4.30.0 - 4.30.5M
Arista Networks/EOS
4.31.0 - 4.31.1F
Published
Jun 04, 2026
Tracked Since
Jun 05, 2026