CVE-2024-6858 - CVE House
Back to Database
Status published Unknown CVE-2024-6858

In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.

Affected Vendor

Arista Networks

View all reports →

Affected Software

EOS
Vulnerable Versions:
4.31.0, 4.30.0, 4.29.0, 4.28.10

Timeline

Official Publish: June 4th, 2026
Last Modified: June 5th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.