Impact
The vulnerability arises when MACsec and egress ACLs are configured on the same interface in Arista EOS. In this configuration, the ACL policies may not be enforced for packets leaving the port, allowing traffic that should be filtered or denied. This represents an access control flaw (CWE‑284) that could enable an attacker to inject or exfiltrate traffic that is otherwise blocked.
Affected Systems
affected products are Arista Networks EOS firmware across several release trains. Versions prior to 4.32.1F in the 4.32.x train, 4.31.3M in the 4.31.x train, 4.30.7M in the 4.30.x train, 4.29.8M in the 4.29.x train, and 4.28.11M in the 4.28.x train are vulnerable. All releases before these specific build numbers lack the remedy.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk, and while EPSS is not available, the vulnerability is not currently listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector is an attacker with ability to send packets from the affected interface, which could be local or remote depending on network configuration. The flaw directly impacts compliance and security policy enforcement.
OpenCVE Enrichment