Severity
5.3MEDIUMNVD
EPSS
0.2%
top 52.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 4
Latest updateAug 18

Description

On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captive-portal authentication during ASU would be impacted with this bug.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages1 packages

CVEListV5arista_networks/eos4.32.04.32.4M+2

🔴Vulnerability Details

8
GHSA
GHSA-8fjr-734h-7jj5: On affected platforms running Arista EOS with 8022025-03-04
CVEList
On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being inst2025-03-04
GHSA
@lobehub/chat Server Side Request Forgery vulnerability2024-11-26
GHSA
MobSF vulnerable to Open Redirect in Login Redirect2024-07-31
GHSA
Hono vulnerable to Restricted Directory Traversal in serveStatic with deno2024-04-23

💥Exploits & PoCs

1
Exploit-DB
BigAnt Office Messenger 5.6.06 - SQL Injection2025-08-18

📋Vendor Advisories

6
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-89042024-10-01
Chrome
Stable Channel Update for Desktop: CVE-2024-91202024-09-24
Chrome
Stable Channel Update for Desktop: CVE-2024-69882024-07-23
Cisco
Cisco IOS XR Software SSH Privilege Escalation Vulnerability2024-03-13
Chrome
Stable Channel Update for Desktop: CVE-2024-31682024-02-20
CVE-2024-8000 — Arista Networks EOS vulnerability | cvebase