CVE Watchtower


← Back to CVE List

CVE-2024-27890NVD

Vulnerability Summary

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
Severity Level
CRITICAL(9.6)
Published Date
Jun 4, 2026
Last Modified
Jun 4, 2026
Exploitation Status
UNKNOWN
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityNone
IntegrityHigh
AvailabilityHigh