CVE-2024-27892: Arista Networks Eos

Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

Affected products

  • Arista Networks Eos: from 4.31.0, up to and including 4.31.2F; from 4.30.0, up to and including 4.30.5M; from 4.29.0, up to and including 4.29.7M; from 4.28.0, up to and including 4.28.10M; from 4.27.0, up to and including 4.27.8M; from 4.26.0, up to and including 4.26.9M; …

Published 2026-06-04. Last modified 2026-07-22.