CVE-2023-24511: On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process.
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulnerability does not have any confidentiality or integrity impacts to the system.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24511?
CVE-2023-24511 is rated as a medium severity vulnerability due to its potential to cause memory leaks and disrupt SNMP services.
How do I fix CVE-2023-24511?
To fix CVE-2023-24511, upgrade to a version of Arista EOS above 4.29.2f or the specified patched versions in their advisory.
What systems are affected by CVE-2023-24511?
CVE-2023-24511 affects Arista EOS versions 4.26.0 through 4.26.10m, 4.27.0 through 4.27.9m, 4.28.0 through 4.28.6m, and up to 4.29.2f.
What impact does CVE-2023-24511 have?
CVE-2023-24511 can lead to a memory leak in the snmpd process, causing SNMP requests to time out until the process is restarted.
Is there a workaround for CVE-2023-24511?
There is no official workaround for CVE-2023-24511; upgrading to a patched version is the recommended mitigation.