Junglewise Threat Intelligence

CVE-2024-6858: Arista EOS authentication bypass in 802.1X multi-auth mode

CVE-2024-6858 · Severity: info · Published 2026-06-04

Technologies: Arista Eos. Vendors: Arista.

Executive brief

A security flaw in Arista EOS network switches could allow unauthorized devices to gain access to a protected network port. This occurs when the switch is configured for 802.1X authentication in multi-auth mode and a specific type of device is present in the fallback network. An attacker could potentially bypass security controls to access internal network resources without providing valid credentials.

Technical details

A vulnerability in Arista EOS exists when 802.1X port-based authentication is configured in multi-auth mode. The issue arises from improper validation of input types (CWE-1287) where unauthenticated hosts may be granted access to a switch port if an EAPOL-capable device is already present in the configured fallback VLAN. This allows an adjacent attacker to bypass network access control (NAC) mechanisms. The vulnerability affects specific versions of EOS; users are advised to consult Arista security advisory 0103 for specific software fix versions.

Affected products

  • Arista EOS

Timeline

  • 2026-06-04: disclosed: Initial publication of the CVE and Arista advisory.

References

Related threats