Vulnerability record · CVE-2026-7473 · published 5 June 2026
CVE-2026-7473: Arista EOS tunnel decapsulation protocol type not verified
Arista · Eos
Arista EOS switches configured for tunnel decapsulation (VXLAN, decap-groups, or GRE tunnel interfaces) fail to verify the tunnel protocol type, so they decapsulate and forward unexpected tunneled packets whose destination IP matches the configured decapsulation IP. This lets non-configured tunnel traffic be processed by the switch, and the issue has been reported as exploited in the wild.
Description
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a short remediation deadline, though the CVSS 4.0 score is only 6.9 (Medium) with limited integrity impact.
What it is
Arista EOS switches configured for tunnel decapsulation (VXLAN, decap-groups, or GRE tunnel interfaces) fail to verify the tunnel protocol type, so they decapsulate and forward unexpected tunneled packets whose destination IP matches the configured decapsulation IP. This lets non-configured tunnel traffic be processed by the switch, and the issue has been reported as exploited in the wild.
Impact
An attacker can inject tunneled traffic that the switch will decapsulate and forward, potentially reaching internal segments or services that should not receive that traffic. The CVSS 4.0 vector shows only low integrity impact (VI:L, SI:L) with no confidentiality or availability impact.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS 4.0 vector. The switch must have a tunnel decapsulation configuration present, such as VXLAN, decap-groups, or a GRE tunnel interface.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2026-06-09 with a remediation due date of 2026-06-23, and the NVD description states it has been reported as exploited in the wild. EPSS 30-day probability is 0.01108 (64.2nd percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor fix from Arista security advisory 0137 (referenced as Mitigation/Vendor Advisory) as the first action.
- Follow CISA KEV required action and BOD 22-01 guidance; if no mitigation is available, discontinue use of the affected product.
- Review and restrict tunnel decapsulation configurations (VXLAN, decap-groups, GRE) so only intended tunnel protocols and sources are accepted.
- Filter or block unexpected tunneled traffic at network boundaries and on affected switches where feasible.
Detection
- Monitor switch logs and telemetry for decapsulation of unexpected tunnel protocols or tunnel traffic from non-configured sources.
- Alert on tunneled packets whose destination IP matches a configured decapsulation IP but whose protocol type does not match the configured tunnel type.
- Review network flow data for anomalous forwarding of decapsulated traffic toward internal segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-7473 to the Known Exploited Vulnerabilities catalog on 9 June 2026 as "Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137 | Broken Link |
| https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137 | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7473 | US Government Resource |
Track CVE-2026-7473 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-7473), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.