---
id: CVE-2026-7473
title: >-
  On affected platforms running Arista EOS where a tunnel decapsulation
  configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE
  (Generic Routing Encapsulation) tunnel interface—is present, the switch will
  incorrectly d…
summary: >-
  On affected platforms running Arista EOS where a tunnel decapsulation
  configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE
  (Generic Routing Encapsulation) tunnel interface—is present, the switch will
  incorrectly d…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-1023
vendor: arista
product: eos
affected:
  - eos
published: '2026-06-05'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:43.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7473'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137
    label: psirt@arista.com
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7473
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-06-10T03:57:42.438072Z'
epss: 0.00649
epssPercentile: 0.49395
kev: true
kevDateAdded: '2026-06-09'
kevDueDate: '2026-06-23'
kevRansomware: false
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/fevar54/CVE-2026-7473---Arista-EOS-Tunnel-Decapsulation-Bypass
  checkedAt: '2026-10-07T20:47:22.833Z'
ingestedAt: '2026-10-07T20:46:46.954Z'
---

## Overview

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.



This issue has been reported as being exploited in the wild.

## Affected

- `eos`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
