CVE-2024-6858: In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.28.11M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.29.8M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.30.6M - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.31.2F
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6858?
The severity of CVE-2024-6858 is rated at 44, indicating a significant security risk.
How do I fix CVE-2024-6858?
To fix CVE-2024-6858, upgrade to the latest remediated software version provided by Arista EOS.
What does CVE-2024-6858 affect?
CVE-2024-6858 affects Arista’s EOS when operating in 802.1X mode, specifically concerning unauthenticated hosts accessing switch ports.
What happens if CVE-2024-6858 is exploited?
If CVE-2024-6858 is exploited, an unauthenticated host may gain unauthorized access to a switch port due to the presence of an EAPOL capable device.
Is CVE-2024-6858 easy to exploit?
The exploitation of CVE-2024-6858 may vary in difficulty depending on the network setup and presence of an EAPOL capable device.