Cyber Resilience

CVE-2026-7473

MediumCISA KEVActive ExploitationUpdated

Published: 05 June 2026

Published
05 June 2026
Modified
17 June 2026
KEV Added
09 June 2026
Patch
CVSS Score v4 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0084 53.2th percentile
Risk Priority 100 floored blend · peak EPSS

Summary

CVE-2026-7473 is a medium-severity Incomplete Comparison with Missing Factors (CWE-1023) vulnerability in Arista Eos. Its CVSS base score is 6.9 (Medium).

Operationally, ranked in the top 46.8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

EU & UK References

Vulnerability details

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination…

more

IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

CWE(s)
KEV Date Added
09 June 2026

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

Insufficient information to map techniques.
Confidence: LOW · MITRE ATT&CK Enterprise v19.0

Affected Assets

arista
eos
all versions

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References