← Back to CVE List
CVE-2026-7473NVD
Vulnerability Summary
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.
This issue has been reported as being exploited in the wild.
This issue has been reported as being exploited in the wild.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)Low
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.8 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Arista Networks EOS >= 4.36.0
- Arista Networks EOS >= 4.35.0 and <= 4.35
- Arista Networks EOS >= 4.34.0 and <= 4.34
- Arista Networks EOS >= 4.33.0 and <= 4.33
- Arista Networks EOS >= 4.32.0 and <= 4.32
- Arista Networks EOS >= 4.31.0 and <= 4.31
- Arista Networks EOS >= * and <= 4.30
- Arista Networks EOS 4.35
- Arista Networks EOS 4.34
- Arista Networks EOS 4.33
- Arista Networks EOS 4.32
- Arista Networks EOS 4.31
- Arista Networks EOS 4.30