CVE-2024-27891: On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.
On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.28.11M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.29.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.30.7M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.31.3M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.32.1F
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27891?
The severity of CVE-2024-27891 is medium with a score of 5.3.
What platforms are affected by CVE-2024-27891?
CVE-2024-27891 affects platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces.
How do I fix CVE-2024-27891?
To fix CVE-2024-27891, upgrade to a remediated software version of Arista EOS at your earliest convenience.
What issues does CVE-2024-27891 cause?
CVE-2024-27891 can cause ACL policies to not be enforced for packets egressing on affected ports, leading to incorrect packet handling.
When was CVE-2024-27891 published?
CVE-2024-27891 was published on June 4, 2026.