SB2023041756 - Denial of service in Arista EOS SNMP



SB2023041756 - Denial of service in Arista EOS SNMP

Published: April 17, 2023 Updated: May 17, 2025

Security Bulletin ID SB2023041756
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Memory leak (CVE-ID: CVE-2023-24511)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulnerability does not have any confidentiality or integrity impacts to the system. A remote attacker can perform a denial of service attack.


Remediation

Install update from vendor's website.