CVE-2024-27890: Arista Networks Eos

Critical severity, CVSS 9.6. EPSS: 4.4% chance of exploitation in the next 30 days.

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

Affected products

  • Arista Networks Eos: from 4.29.0, up to and including 4.29.7M; from 4.28.0, up to and including 4.28.10M; from 4.27.0, up to and including 4.27.8M; from 4.26.0, up to and including 4.26.9M; from 4.25.0, up to and including 4.25.10M; from 4.24.0, up to and including 4.24.11M

Published 2026-06-04. Last modified 2026-07-22.