← Vulnerability feed

Vulnerability record · CVE-2026-7473 · published 5 June 2026

CVE-2026-7473: Arista EOS tunnel decapsulation protocol type not verified

Arista · Eos

Arista EOS switches configured for tunnel decapsulation (VXLAN, decap-groups, or GRE tunnel interfaces) fail to verify the tunnel protocol type, so they decapsulate and forward unexpected tunneled packets whose destination IP matches the configured decapsulation IP. This lets non-configured tunnel traffic be processed by the switch, and the issue has been reported as exploited in the wild.

6.9 CVSS 4.0 Medium CISA KEV since 9 Jun 2026 EPSS 0.65% · top 51.0% CWE-1023 · CWE-1023
6.9CVSS 4.0 base score
0.65%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a short remediation deadline, though the CVSS 4.0 score is only 6.9 (Medium) with limited integrity impact.

What it is

Arista EOS switches configured for tunnel decapsulation (VXLAN, decap-groups, or GRE tunnel interfaces) fail to verify the tunnel protocol type, so they decapsulate and forward unexpected tunneled packets whose destination IP matches the configured decapsulation IP. This lets non-configured tunnel traffic be processed by the switch, and the issue has been reported as exploited in the wild.

Impact

An attacker can inject tunneled traffic that the switch will decapsulate and forward, potentially reaching internal segments or services that should not receive that traffic. The CVSS 4.0 vector shows only low integrity impact (VI:L, SI:L) with no confidentiality or availability impact.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS 4.0 vector. The switch must have a tunnel decapsulation configuration present, such as VXLAN, decap-groups, or a GRE tunnel interface.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2026-06-09 with a remediation due date of 2026-06-23, and the NVD description states it has been reported as exploited in the wild. EPSS 30-day probability is 0.01108 (64.2nd percentile), and no ransomware campaign use is documented.

What to do

  • Apply the vendor fix from Arista security advisory 0137 (referenced as Mitigation/Vendor Advisory) as the first action.
  • Follow CISA KEV required action and BOD 22-01 guidance; if no mitigation is available, discontinue use of the affected product.
  • Review and restrict tunnel decapsulation configurations (VXLAN, decap-groups, GRE) so only intended tunnel protocols and sources are accepted.
  • Filter or block unexpected tunneled traffic at network boundaries and on affected switches where feasible.

Detection

  • Monitor switch logs and telemetry for decapsulation of unexpected tunnel protocols or tunnel traffic from non-configured sources.
  • Alert on tunneled packets whose destination IP matches a configured decapsulation IP but whose protocol type does not match the configured tunnel type.
  • Review network flow data for anomalous forwarding of decapsulated traffic toward internal segments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-7473 to the Known Exploited Vulnerabilities catalog on 9 June 2026 as "Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7473 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed10.0CVE-2015-8236Arista eos permissions and access controls vulnerabilityArista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to …EPSS 4.2%9.8CVE-2021-28503Arista eos improper authentication vulnerabilityThe impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, whi…EPSS 0.74%9.8CVE-2020-10188netkit telnetd buffer overflow allows remote code executionA buffer overflow in utility.c in netkit telnetd through 0.17, involving the netclear and nextitem functions, can be triggered by short writes or urg…EPSS 74%analysed9.8CVE-2017-18017Linux kernel xt_TCPMSS use-after-free in tcpmss_mangle_packetThe tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11 and 4.9.x before 4.9.36 contains a use-after-free that…EPSS 53%analysed9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed9.3CVE-2015-5165Xen use of uninitialized resource vulnerabilityThe C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read pro…EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2026-7473), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.