Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3198 articles · 183323 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2024-27891EXPLOITEDPATCHED
arista · eos

On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.

Description

On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.

Affected Products

VendorProductVersions
aristaeos4.32.0, 4.31.0, 4.30.0, 4.29.0, 4.28.0, 4.27.2F

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
aristaeoscert_advisory90%

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/19908-security-advisory-0102

Related News (2 articles)

Tier B
BSI Advisories59d ago
[UPDATE] [mittel] Arista EOS: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier C
VulDB59d ago
CVE-2024-27891 | Arista EOS up to 4.32.0.1F access control
→ No new info (linked only)
CVSS 3.15.3 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.28.0
CWECWE-284
PublishedJun 4, 2026
Last enriched59d agov2
Trending Score0
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16812
VeloCloud Orchestrator OS Command Injection
Trending: 82
MEDIUMCVE-2026-7473EXPKEV
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
NONECVE-2023-5502EXP
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.
HIGHCVE-2025-8873EXP
Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
HIGHCVE-2025-5088
Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 4, 2026
Discovered by ZDM
Jun 4, 2026
Updated: severity, affectedVersions, activelyExploited
Jun 4, 2026
Actively Exploited
Jun 5, 2026
Patch Available
Jun 5, 2026

Version History

v2
Last enriched 59d ago
v2Tier C59d ago

Updated severity to CRITICAL, added new affected version 4.32.0.1F, and marked the vulnerability as actively exploited.

severityaffectedVersionsactivelyExploited
via VulDB
v159d ago

Initial creation