CVE-2024-27890: Arista EOS OpenConfig gNMI Access Control Bypass (CRITICAL)
Arista EOS switches running OpenConfig are vulnerable to unauthorized configuration changes through the gNMI (gRPC Network Management Interface) protocol. An authenticated user can craft a gNMI Set request that bypasses access controls and applies unexpected configuration to the switch, potentially compromising network operations or enabling lateral movement. The vulnerability requires valid credentials but affects the system's integrity with no authentication boundary respected for certain configuration operations.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 9.6 CRITICAL · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
- Weaknesses (CWE)
- CWE-306
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-04 / 2026-06-17
NVD description (verbatim)
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2024-27890 is a missing authentication/authorization control vulnerability (CWE-306) in Arista EOS when OpenConfig is configured. The gNMI Set operation fails to properly enforce access controls, allowing a logged-in user to submit configuration changes that should be rejected based on role or policy. The CVSS 3.1 score of 9.6 reflects the critical nature: network-adjacent attack vector, low complexity, privileged user required, but with scope change and high impact to both integrity and availability. An attacker with valid credentials can alter switch configurations without appropriate authorization checks.
Business impact
Unauthorized configuration changes to production network switches can disrupt service availability, enable traffic interception or redirection, facilitate lateral movement within the network, or establish persistence mechanisms. In multi-tenant or compliance-sensitive environments, this represents a serious control violation—allowing authenticated users to exceed their assigned privileges violates the principle of least privilege and can trigger breach notification obligations. Recovery requires identifying unauthorized changes, reverting configurations, and potentially auditing all switch activity during the exposure window.
Affected systems
Arista EOS platforms with OpenConfig configuration are affected. The vendor product list was not provided in the advisory data; verify the exact EOS versions and OpenConfig deployments in your environment against the official Arista security advisory. This typically affects modern Arista switch models that support gNMI management.
Exploitability
Exploitation requires valid credentials (low privilege sufficient), but no network authentication is required beyond that. The attack is deterministic—the attacker need only craft a properly formatted gNMI Set request to a reachable management interface. No user interaction or complex setup is required. The relatively low barrier to exploitation combined with the critical impact makes this a high-priority threat for networks with Arista infrastructure and user access to management interfaces.
Remediation
Patch affected Arista EOS instances to a version that corrects the gNMI access control validation. Consult the official Arista security advisory for specific patched versions. In the interim, restrict network and administrative access to the gNMI management interface, enforce strong authentication and role-based access control (RBAC), monitor gNMI Set operations for anomalies, and consider disabling OpenConfig management if not actively required. Review audit logs to identify any unauthorized configuration changes that may have occurred during exposure.
Patch guidance
Apply the security update from Arista that addresses gNMI access control enforcement. The specific patched EOS versions should be identified in the vendor advisory—verify the patch version against your current software baseline and test in a non-production environment before deployment. Arista typically provides patches through their standard software release channels; consult their advisory for timeline and availability.
Detection guidance
Monitor gNMI Set requests sent to OpenConfig-enabled switches, particularly those originating from unexpected sources or users. Log and alert on configuration changes applied via gNMI that deviate from change control procedures. Review authentication and authorization logs on management interfaces for failed or suspicious access patterns. Network-based detection should flag unexpected management protocol traffic to switch IP addresses, especially from internal sources that should not be managing network infrastructure.
Why prioritize this
CVSS 9.6 (Critical) with scope change, high integrity and availability impact, and low barrier to exploitation justify immediate prioritization. Any Arista environment running OpenConfig should be assessed and patched urgently. The vulnerability allows lateral privilege escalation and configuration tampering by authenticated users—a foundational security boundary violation in network infrastructure.
Risk score, explained
The 9.6 CVSS score reflects a network-accessible vulnerability requiring only low privilege and basic authentication, but capable of affecting multiple systems (scope change) with high impact to both system integrity (configuration tampering) and availability (potential service disruption). The lack of significant complexity or user interaction requirements elevates risk despite the authentication requirement. In network environments where Arista switches are critical, this is a top-tier threat.
Frequently asked questions
Do I need to be an administrator to exploit this vulnerability?
No. The vulnerability can be exploited by any authenticated user with valid credentials, even those with low privilege levels. The access control bypass allows unauthorized users to execute configuration changes that should be restricted to administrators.
What happens if my Arista switches do not have OpenConfig enabled?
This vulnerability specifically affects EOS platforms with OpenConfig configured. If OpenConfig is not enabled on your switches, this particular vulnerability does not apply. However, verify your OpenConfig status and consult Arista documentation if uncertain.
Can this be exploited remotely?
Yes. The vulnerability is in the gNMI management protocol, which is typically accessible over the network to authorized management stations. Any device that can reach the management interface and provide valid credentials can potentially exploit this flaw.
What should I do if I cannot patch immediately?
Implement network segmentation to restrict access to management interfaces, enforce strong credentials and multi-factor authentication, closely monitor gNMI traffic and configuration changes, and consider temporarily disabling OpenConfig if not mission-critical. Prepare a rollback plan in case unauthorized configurations are detected.
This analysis is provided for informational purposes based on publicly disclosed vulnerability data. Verify all technical details, affected versions, and patch availability against official Arista security advisories and vendor communications. Testing should be performed in non-production environments. This document does not constitute professional security advice; consult qualified security professionals for environment-specific risk assessment and remediation planning. Source: NVD (public-domain), retrieved 2026-07-14. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2023-54350HIGHWordPress Augmented-Reality Plugin Remote Code Execution
- CVE-2026-10243HIGHSmart Parking System 1.0 Authentication Bypass – Remote Admin Access
- CVE-2026-10281HIGHEnderfga claw-orchestrator Authentication Bypass – Patch Available
- CVE-2026-10283MEDIUMBottelet DaybydayCRM Authentication Bypass in Settings Handler
- CVE-2026-10617HIGHGoClaw Webhook Authentication Bypass – Remote Exploitation
- CVE-2026-11238MEDIUMChrome DevTools Memory Disclosure via Malicious Extension
- CVE-2026-24088HIGHQualcomm Bootloader Cryptographic Verification Flaw (CVSS 8.2)
- CVE-2026-24090HIGHQualcomm Partition Table Cryptographic Flaw Enables Boot Modification
Preview — this page is review (quality 0.893). high-value: hold for review.