peter bassill · operator
$ cve CVE-2026-7473 JSON

CVE-2026-7473 KEV

5.8
MEDIUM · CVSS 3.1 · EPSS 0.6% (pctl 49)

Patch first

On CISA KEV — known exploited in the wild, due 2026-06-23.

Description

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

Scoring

CVSS5.8 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS0.65% — more likely to be exploited than 49% of all CVEs
WeaknessCWE-1023
On CISA KEVyes — remediate by 2026-06-23
Public exploitnone known
Published2026-06-05
Last modified2026-06-17

CISA KEV

NameArista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Added2026-06-09
Due2026-06-23
Vendor / productArista / Extensible Operating System
Ransomware usenone reported

Affected (40)

VendorProduct
arista7020sr-24c2
arista7020sr-32c2
arista7020srg-24c2
arista7020tr-48
arista7020tra-48
arista7280cr-48
arista7280cr2-60
arista7280cr2a-30
arista7280cr2a-60
arista7280cr2k-30
arista7280cr2k-60
arista7280cr2m-30
arista7280cr3-32d4
arista7280cr3-32p4
arista7280cr3-36s
arista7280cr3-96
arista7280cr3a-24d12
arista7280cr3a-48d6
arista7280cr3a-72
arista7280cr3ak-24d12
arista7280cr3ak-48d6
arista7280cr3ak-72
arista7280cr3am-24d12
arista7280cr3am-48d6
arista7280cr3am-72
arista7280cr3mk-32d4s
arista7280cr3mk-32p4s
arista7280dr3-24
arista7280dr3a-36
arista7280dr3a-54
arista7280dr3ak-36
arista7280dr3ak-54
arista7280dr3am-36
arista7280dr3am-54
arista7280pr3-24
arista7280qr-c36
arista7280qr-c36-m
arista7280qr-c72
arista7280qra-c36s
aristaeos

References

→ the Explorer  ·  watch your stack  ·  NVD