CVE-2024-27890: On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled).
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.28.10.1Patch CVE-2024-27890 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.29.7Patch CVE-2024-27890 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.30.5Patch CVE-2024-27890 - Configuration
Ensure the applied hotfix is persistent across reboots by running the command: copy installed-extensions boot-extensions
Arista EOS extensions copy installed-extensions boot-extensions = run to ensure the hotfix patch is persistent across reboots - Operational
Expect the OpenConfig/Octa process to restart if you install/uninstall the SWIX for the hotfix; services may be unavailable for up to one minute.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27890?
CVE-2024-27890 has a critical severity rating of 9.6.
How do I fix CVE-2024-27890?
To fix CVE-2024-27890, upgrade to a remediated software version as recommended by Arista.
What platforms are affected by CVE-2024-27890?
CVE-2024-27890 affects platforms running Arista EOS with OpenConfig configured.
What risks does CVE-2024-27890 pose?
CVE-2024-27890 can lead to unauthorized configuration changes being applied to the switch.
Is there a hotfix available for CVE-2024-27890?
Yes, a hotfix can be applied to specific releases to remediate CVE-2024-27890.