August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-7473NVD

Vulnerability Summary

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.



This issue has been reported as being exploited in the wild.
Severity Level
MEDIUM(5.8)
Published Date
Jun 5, 2026
Last Modified
Jun 10, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
0.84%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityNone
IntegrityLow
AvailabilityNone