← Back to Vulnerability Reports CVE Intelligence

CVE-2026-7473

Arista Extensible Operating SystemMEDIUM · CVSS 5.8 In the wild In CISA KEV

What is CVE-2026-7473?

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

CVSS5.8 NVD 3.1
SeverityMEDIUM
Exploitation In the wild In CISA KEV
EPSS<1% · P9
Triage statusActive Exploit
ActionPatch immediately
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CWECWE-1023
NVD published2026-06-05
NVD last modified2026-06-09

CISA Known Exploited Vulnerability

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Added to KEV2026-06-09
Federal patch deadline2026-06-23
Known ransomware useUnknown

Affected product

Arista Extensible Operating System

NVD also lists CPE entries for: Arista Eos, Arista 7020sr-24c2, Arista 7020sr-32c2, Arista 7020srg-24c2, Arista 7020tr-48

Remediation Steps

  1. Apply the vendor security patch from Arista Networks
  2. Verify patch deployment across all affected EOS instances
  3. Monitor network device logs for suspicious activity
  4. Coordinate patching during maintenance windows to minimize service disruption

Coverage on defend.network

🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.