GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS (MACsec with egress ACLs): TENANT ISOLATION: on interfaces with both MACsec and egress ACLs configured

CVE-2024-27891Firmware, BMC & network fabricArista Security Advisory 0102curated

Impact

TENANT ISOLATION: on interfaces with both MACsec and egress ACLs configured, the egress ACL is not enforced for packets leaving those ports. The combination — link encryption plus egress filtering — is exactly what you deploy on inter-site or inter-pod links carrying multiple tenants, so the failure lands on the highest-trust links in the build.

Who can reach it

Traffic egressing an interface configured with both MACsec and an egress ACL. No attacker capability needed.

What to do

EOS upgrade plus reload. Interim: move the filtering to the ingress direction on the far side of the link, which is a live config change and restores enforcement without touching MACsec.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.