CVE-2026-7473

Confirmed PUBLISHED

Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass

Arista Networks · EOS

4 days faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.9 Medium EPSS 0.8%

At a Glance

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

cisa
CVE Published
Jun 05, 2026
Exploitation Reported
Jun 05, 2026
CVSS
6.9 Medium
EPSS
0.8%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Arista Networks
EOS

4.36.0

Affected
Arista Networks
EOS

4.35.0 to <= 4.35

Affected
Arista Networks
EOS

4.34.0 to <= 4.34

Affected
Arista Networks
EOS

4.33.0 to <= 4.33

Affected
Arista Networks
EOS

4.32.0 to <= 4.32

Affected
Arista Networks
EOS

4.31.0 to <= 4.31

Affected
Arista Networks
EOS

* to <= 4.30

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.