CVE-2024-7095

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 10, 2025

Summary

CVE-2024-7095 is a vulnerability affecting Arista EOS platforms with SNMP (Simple Network Management Protocol) configured. If the "snmp-server transmit max-size" setting is enabled, a maliciously crafted SNMP packet can trigger the snmpd process to leak memory. This memory leak may lead to snmpd termination, causing SNMP requests to time out until the process is restarted. Consequently, increased memory pressure on the switch could potentially result in other processes being unexpectedly terminated as well.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share