CVE-2024-27892: On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.28.10.1Patch CVE-2024-27892 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.29.7Patch CVE-2024-27892 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.30.5Patch CVE-2024-27892 - Configuration
Plan for the OpenConfig/Octa process to restart when installing/uninstalling the SWIX; services may be unavailable for up to one minute.
Arista EOS SWIX (hotfix installed/uninstalled) OpenConfig/Octa process = restarts - Operational
After applying the hotfix/upgrade, make the patch persistent across reboots by running: copy installed-extensions boot-extensions.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27892?
CVE-2024-27892 has a critical severity rating of 9.6.
How do I fix CVE-2024-27892?
To remediate CVE-2024-27892, upgrade to a remediated software version provided by Arista.
What does CVE-2024-27892 affect?
CVE-2024-27892 affects platforms running Arista EOS with OpenConfig configured.
What is the risk of CVE-2024-27892?
CVE-2024-27892 poses a risk of unexpected configuration being applied to the switch.
What is the impact of CVE-2024-27892?
The impact of CVE-2024-27892 is that it allows gNMI Set requests to be processed when they should be rejected.