CVE-2023-24511 - CVE House
Back to Database
Status published Medium CVE-2023-24511

On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process.

Vulnerability Description

On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulnerability does not have any confidentiality or integrity impacts to the system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-24511

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Arista Networks

View all reports →

Affected Software

EOS
Vulnerable Versions:
4.28.0 4.28.5.1M, 4.27.0 4.27.8.1M, 4.26.0 4.26.9M, 4.25.0 4.25.10M, 4.24.0 4.24.11M, 4.29.0

Timeline

Official Publish: April 12th, 2023
Last Modified: February 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)