GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is not

CVSS 5.3CVE-2024-27891Firmware, BMC & network fabricArista Security Advisory 0102curated

Impact

On interfaces with both MACsec and egress ACLs configured, the egress ACL is not enforced for packets leaving those ports. The combination — link encryption plus egress filtering — is exactly what you deploy on inter-site or inter-pod links carrying multiple tenants, so the failure lands on the highest-trust links in the build.

Who can reach it

Traffic egressing an interface configured with both MACsec and an egress ACL. No attacker capability needed.

What to do

EOS upgrade plus reload. Interim: move the filtering to the ingress direction on the far side of the link, which is a live config change and restores enforcement without touching MACsec.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.