CVE-2024-6858: Arista Networks Eos
Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
Affected products
- Arista Networks Eos: from 4.31.0, up to and including 4.31.1F; from 4.30.0, up to and including 4.30.5M; from 4.29.0, up to and including 4.29.7M; from 4.28.10, up to and including 4.28.10.1M
Published 2026-06-04. Last modified 2026-07-22.