CVE-2024-27890 - Critical auth bypass in Arista EOS with OpenConfig. gNMI Set requests improperly accepted, risking unauthorized config changes. CVSS 9.6. No patch available yet. Monitor and restrict access now. #CVE #Arista #infosec

The #Arista community site is such a treasure of information. I regularly find answer to very specific questions such as this one : https://arista.my.site.com/AristaCommunity/s/question/0D55w0000BMF9kdCQD/how-to-mirror-filter-vxaln-vni (on how to filter mirrored packets, per-VNI, in hardware, so you do not overwhelm the CPU)
And having asked a question there, I was impressed by the response time from Arista employees !
Quick BGP fixing...
When using Arista, remember to check it before 😬
#NetworkEngineering #Network #Engineer #BGP #Arista #containerlab
In this excerpt of a TrendAI Research Services vulnerability report, Jonathan Lein and Simon Humbert of the TrendAI Research team detail a recently patched command injection vulnerability in the Arista NG Firewall. This bug was originally discovered by Gereon Huppertz and reported through the Tren