CVE-2024-27891: Arista Networks Eos
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.
Affected products
- Arista Networks Eos: from 4.32.0, up to and including 4.32.0.1F; from 4.31.0, up to and including 4.31.2F; from 4.30.0, up to and including 4.30.6M; from 4.29.0, up to and including 4.29.7M; from 4.28.0, up to and including 4.28.10.1M; from 4.27.2F, before 4.28.0 (fixed in 4.28.0)
Published 2026-06-04. Last modified 2026-07-22.