vulnerability

security-advisory-0107

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
Published
Nov 19, 2024
Added
Nov 22, 2024
Modified
Jan 14, 2026

Description

On affected platforms running Arista EOS with SNMP configured, if "snmp-server transmit max-size" is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out until snmpd is restarted) and memory pressure for other processes on the switch. Increased memory pressure can cause processes other than snmpd to be at risk for unexpected termination as well. This was discovered internally by Arista and we are not aware of any malicious uses of this issue in customer networks.

Solution

upgrade-solution-cve-2024-7095
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.