{"id":"CVE-2026-7473","title":"On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly d…","summary":"On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly d…","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","cwe":["CWE-1023"],"vendor":"arista","product":"eos","affected":["eos"],"published":"2026-06-05","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:43.843","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7473","references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137","label":"psirt@arista.com"},{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7473","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-06-10T03:57:42.438072Z"},"epss":0.00649,"epssPercentile":0.49395,"kev":true,"kevDateAdded":"2026-06-09","kevDueDate":"2026-06-23","kevRansomware":false,"exploits":{"github":1,"githubRepos":["https://github.com/fevar54/CVE-2026-7473---Arista-EOS-Tunnel-Decapsulation-Bypass"],"checkedAt":"2026-10-07T20:47:22.833Z"},"ingestedAt":"2026-10-07T20:46:46.954Z","slug":"CVE-2026-7473","body":"## Overview\n\nOn affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.\n\n\n\nThis issue has been reported as being exploited in the wild.\n\n## Affected\n\n- `eos`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":31.9,"likelihood":0.1,"exploitation":25,"ransomware":0},"changes":[]}