CVE-2024-27890: On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled).

Published Jun 4, 2026
·
Updated

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

Affected Software

1 affected component
Arista Arista EOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.28.10.1Patch CVE-2024-27890
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.29.7Patch CVE-2024-27890
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.30.5Patch CVE-2024-27890
  4. Configuration

    Ensure the applied hotfix is persistent across reboots by running the command: copy installed-extensions boot-extensions

    Arista EOS extensions copy installed-extensions boot-extensions = run to ensure the hotfix patch is persistent across reboots
  5. Operational

    Expect the OpenConfig/Octa process to restart if you install/uninstall the SWIX for the hotfix; services may be unavailable for up to one minute.

Event History

Jun 4, 2026
CVE Published
via MITRE·10:27 PM
Data Sourced
via MITRE·10:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-27890?

CVE-2024-27890 has a critical severity rating of 9.6.

2

How do I fix CVE-2024-27890?

To fix CVE-2024-27890, upgrade to a remediated software version as recommended by Arista.

3

What platforms are affected by CVE-2024-27890?

CVE-2024-27890 affects platforms running Arista EOS with OpenConfig configured.

4

What risks does CVE-2024-27890 pose?

CVE-2024-27890 can lead to unauthorized configuration changes being applied to the switch.

5

Is there a hotfix available for CVE-2024-27890?

Yes, a hotfix can be applied to specific releases to remediate CVE-2024-27890.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203