CVE-2024-8000: On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restar
On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart.
Note: supplicants with pending captive-portal authentication during ASU would be impacted with this bug.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8000?
CVE-2024-8000 has a severity rating that indicates a medium-level impact on network security due to potential misconfiguration of ACLs.
How do I fix CVE-2024-8000?
To mitigate CVE-2024-8000, ensure proper configuration and management of ACLs after performing an Accelerated Software Upgrade on Arista EOS.
What platforms are affected by CVE-2024-8000?
CVE-2024-8000 affects platforms running Arista EOS with 802.1X configured.
What conditions trigger CVE-2024-8000?
CVE-2024-8000 is triggered when a dynamic ACL is received from the AAA server during specific conditions after an ASU restart.
Is there a workaround for CVE-2024-8000?
Yes, regularly verify ACL installation and apply configurations to ensure all lines of the dynamic ACL are properly installed.