Executive brief
A security issue has been identified in Arista EOS where network traffic filters (ACLs) may fail to work correctly on certain hardware. This occurs when both encryption (MACsec) and outbound traffic rules are used on the same network port. As a result, sensitive data that should be blocked might be allowed to leave the network, or legitimate traffic might be unintentionally blocked, potentially bypassing security policies.
Technical details
A vulnerability in Arista EOS (CWE-284) results in improper access control enforcement when MACsec and egress Access Control Lists (ACLs) are simultaneously configured on the same interface. The root cause is a failure in the hardware or software logic to correctly apply ACL policies to packets as they exit the port. An attacker can potentially bypass intended network restrictions, leading to unauthorized data egress or unintended traffic denial. The issue is reachable via the network without authentication, though it requires a specific configuration state to be present. Users are advised to consult Arista security advisory 0102 for specific platform impact and remediation steps.
Affected products
- Arista Networks EOS
Timeline
- 2026-06-04: advisory: Security advisory published by Arista Networks