CVE-2024-27891: CWE-284 Improper Access Control in Arista Networks EOS
CVE-2024-27891 is a medium severity vulnerability in Arista Networks EOS where ACL policies may not be enforced on egressing packets if MACsec and egress ACLs are configured on the same interfaces. This improper access control can cause packets to be incorrectly allowed or denied when leaving the affected ports.
AI Analysis
Technical Summary
On Arista EOS platforms running versions 4.27.2F, 4.28.0, 4.29.0, 4.30.0, 4.31.0, and 4.32.0, when MACsec and egress ACLs are configured simultaneously on the same interfaces, the egress ACL policies may fail to be enforced. This results in improper access control (CWE-284), potentially allowing or denying outgoing packets incorrectly. The vulnerability has a CVSS 4.0 base score of 6.9, indicating a medium severity level. No official patch or remediation guidance is currently provided by the vendor, and no known exploits are reported in the wild.
Potential Impact
The vulnerability can cause egress ACL policies to be bypassed or incorrectly applied, leading to potential unauthorized network traffic flow or unintended blocking of legitimate traffic. This may affect network security posture by undermining intended access control policies on affected interfaces.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should review configurations involving MACsec and egress ACLs on the same interfaces and consider temporary workarounds such as disabling one of these features on the same interface if feasible. Monitor vendor communications for updates on patches or official mitigations.
CVE-2024-27891: CWE-284 Improper Access Control in Arista Networks EOS
Description
CVE-2024-27891 is a medium severity vulnerability in Arista Networks EOS where ACL policies may not be enforced on egressing packets if MACsec and egress ACLs are configured on the same interfaces. This improper access control can cause packets to be incorrectly allowed or denied when leaving the affected ports.
CVSS v4.0
Score 6.9medium
Affected software
pkg:github/aristanetworks/eosRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On Arista EOS platforms running versions 4.27.2F, 4.28.0, 4.29.0, 4.30.0, 4.31.0, and 4.32.0, when MACsec and egress ACLs are configured simultaneously on the same interfaces, the egress ACL policies may fail to be enforced. This results in improper access control (CWE-284), potentially allowing or denying outgoing packets incorrectly. The vulnerability has a CVSS 4.0 base score of 6.9, indicating a medium severity level. No official patch or remediation guidance is currently provided by the vendor, and no known exploits are reported in the wild.
Potential Impact
The vulnerability can cause egress ACL policies to be bypassed or incorrectly applied, leading to potential unauthorized network traffic flow or unintended blocking of legitimate traffic. This may affect network security posture by undermining intended access control policies on affected interfaces.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should review configurations involving MACsec and egress ACLs on the same interfaces and consider temporary workarounds such as disabling one of these features on the same interface if feasible. Monitor vendor communications for updates on patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Arista
- Date Reserved
- 2024-02-26T18:06:32.161Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2200c5e29bf47b50d9ecc6
Added to database: 06/04/2026, 22:48:37 UTC
Last enriched: 06/12/2026, 10:28:46 UTC
Last updated: 07/27/2026, 08:51:56 UTC
Views: 59
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.