{
    "id": "CVE-2026-7473",
    "published": "2026-06-05 17:17:02",
    "last_modified": "2026-06-17 11:02:29",
    "cvss_score": "5.8",
    "cvss_severity": "MEDIUM",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
    "cwe": "CWE-1023",
    "description": "On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.\n\n\n\nThis issue has been reported as being exploited in the wild.",
    "epss_score": "0.00649",
    "epss_percentile": "0.49011",
    "kev": 1,
    "kev_due": "2026-06-23",
    "has_exploit": 0,
    "updated_at": "2026-09-26 18:42:47",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2026-06-23."
    },
    "products": [
        {
            "vendor": "arista",
            "product": "7020sr-24c2"
        },
        {
            "vendor": "arista",
            "product": "7020sr-32c2"
        },
        {
            "vendor": "arista",
            "product": "7020srg-24c2"
        },
        {
            "vendor": "arista",
            "product": "7020tr-48"
        },
        {
            "vendor": "arista",
            "product": "7020tra-48"
        },
        {
            "vendor": "arista",
            "product": "7280cr-48"
        },
        {
            "vendor": "arista",
            "product": "7280cr2-60"
        },
        {
            "vendor": "arista",
            "product": "7280cr2a-30"
        },
        {
            "vendor": "arista",
            "product": "7280cr2a-60"
        },
        {
            "vendor": "arista",
            "product": "7280cr2k-30"
        },
        {
            "vendor": "arista",
            "product": "7280cr2k-60"
        },
        {
            "vendor": "arista",
            "product": "7280cr2m-30"
        },
        {
            "vendor": "arista",
            "product": "7280cr3-32d4"
        },
        {
            "vendor": "arista",
            "product": "7280cr3-32p4"
        },
        {
            "vendor": "arista",
            "product": "7280cr3-36s"
        },
        {
            "vendor": "arista",
            "product": "7280cr3-96"
        },
        {
            "vendor": "arista",
            "product": "7280cr3a-24d12"
        },
        {
            "vendor": "arista",
            "product": "7280cr3a-48d6"
        },
        {
            "vendor": "arista",
            "product": "7280cr3a-72"
        },
        {
            "vendor": "arista",
            "product": "7280cr3ak-24d12"
        },
        {
            "vendor": "arista",
            "product": "7280cr3ak-48d6"
        },
        {
            "vendor": "arista",
            "product": "7280cr3ak-72"
        },
        {
            "vendor": "arista",
            "product": "7280cr3am-24d12"
        },
        {
            "vendor": "arista",
            "product": "7280cr3am-48d6"
        },
        {
            "vendor": "arista",
            "product": "7280cr3am-72"
        },
        {
            "vendor": "arista",
            "product": "7280cr3mk-32d4s"
        },
        {
            "vendor": "arista",
            "product": "7280cr3mk-32p4s"
        },
        {
            "vendor": "arista",
            "product": "7280dr3-24"
        },
        {
            "vendor": "arista",
            "product": "7280dr3a-36"
        },
        {
            "vendor": "arista",
            "product": "7280dr3a-54"
        },
        {
            "vendor": "arista",
            "product": "7280dr3ak-36"
        },
        {
            "vendor": "arista",
            "product": "7280dr3ak-54"
        },
        {
            "vendor": "arista",
            "product": "7280dr3am-36"
        },
        {
            "vendor": "arista",
            "product": "7280dr3am-54"
        },
        {
            "vendor": "arista",
            "product": "7280pr3-24"
        },
        {
            "vendor": "arista",
            "product": "7280qr-c36"
        },
        {
            "vendor": "arista",
            "product": "7280qr-c36-m"
        },
        {
            "vendor": "arista",
            "product": "7280qr-c72"
        },
        {
            "vendor": "arista",
            "product": "7280qra-c36s"
        },
        {
            "vendor": "arista",
            "product": "eos"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2026-7473",
        "date_added": "2026-06-09",
        "due_date": "2026-06-23",
        "vendor": "Arista",
        "product": "Extensible Operating System",
        "name": "Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability",
        "ransomware": 0
    },
    "exploits": [],
    "refs_list": [
        "https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137",
        "https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7473"
    ]
}