CVE-2026-7473

Published Jun 5, 2026

Last updated 2 months ago

Exploit knownCVSS medium 6.9
Tunneling protocol
Arista EOS
VXLAN
GRE

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-7473 describes a vulnerability affecting Arista EOS platforms that have a tunnel decapsulation configuration enabled. This includes configurations such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface. The core issue is that the affected switch will incorrectly decapsulate and forward unexpected tunneled packets if their destination IP matches the configured decapsulation IP. This vulnerability arises because the switch fails to verify the tunnel protocol type, which can lead to the processing of non-configured tunnel traffic. This issue has been reported as being actively exploited in the wild and is included in CISA's Known Exploited Vulnerabilities Catalog.

Description
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
Source
psirt@arista.com
NVD status
Analyzed
Products
eos

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Secondary
Base score
5.8
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Exploit added on
Jun 9, 2026
Exploit action due
Jun 23, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@arista.com
CWE-1023

Social media

Hype score
Not currently trending
  1. 00:00 UTC: CVE-2026-7473 disclosed. CISA: CVE-2026-7473 added to Known Exploited Vulnerabilities — Arista Extensible Operating System CVE-2026-7473 added to CISA KEV: Arista Extensible Operating System

    @lyrie_ai

    6 Jul 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🛡️ CVE-2026-7473: Vulnerabilidad crítica en Arista EOS permite reenvío de paquetes túnel no autorizados Análisis técnico del CVE-2026-7473 en Arista EOS: vulnerabilidad de comparación incompleta que permite desencapsulación y reenvío de paquetes túnel maliciosos.

    @CiberPlanetaOrg

    18 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Every so often, a single CVE manages to demonstrate everything that is broken about how we discover, track, and remediate vulnerabilities, and CVE-2026-7473 in Arista EOS is one of those, which is exactly why I wrote it up. https://t.co/BXQdE6WCAj

    @securityweekly

    16 Jun 2026

    212 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Top 3 Cybersecurity Threats 🫠CVE-2026-20245 — Cisco Catalyst SD-WAN Manager (Improper Encoding or Escaping of Output; authenticated local attacker can achieve root execution via crafted file). 🫠CVE-2026-7473 — Arista Extensible Operating System (incomplete tunneled-p

    @Dekryptoes

    12 Jun 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Top 3 Cybersecurity Threats 1. CVE-2026-20245 — Cisco Catalyst SD-WAN Manager (improper output encoding; authenticated local attacker can achieve root execution via crafted file). 2. CVE-2026-7473 — Arista Extensible Operating System (incomplete tunneled-packet handling may l

    @Dekryptoes

    10 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにアリスタネットワークス社EOSのCVE-2026-7473、ChromiumのCVE-2026-11645、Cisco Catalyst SD-WAN ManagerのCVE-2026-20245を追加。対処期限

    @__kokumoto

    9 Jun 2026

    1872 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 🛡️ We added Arista EOS vulnerability CVE-2026-7473, Google Chromium V8 vulnerability CVE-2026-11645, & Cisco Catalyst vulnerability CVE-2026-20245 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecur

    @CISACyber

    9 Jun 2026

    3950 Impressions

    13 Retweets

    29 Likes

    2 Bookmarks

    1 Reply

    3 Quotes

Configurations