Home

Description

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

PUBLISHED Reserved 2024-02-26 | Published 2026-06-04 | Updated 2026-06-05 | Assigner Arista




HIGH: 7.2CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

CRITICAL: 9.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unaffected

4.29.0 (custom)
affected

4.28.0 (custom)
affected

4.27.0 (custom)
affected

4.26.0 (custom)
affected

4.25.0 (custom)
affected

4.24.0 (custom)
affected

References

www.arista.com/...rity-advisory/19862-security-advisory-0099

cve.org (CVE-2024-27890)

nvd.nist.gov (CVE-2024-27890)

Download JSON