CVE-2026-7473
Published: 05 June 2026
Summary
CVE-2026-7473 is a medium-severity Incomplete Comparison with Missing Factors (CWE-1023) vulnerability in Arista Eos. Its CVSS base score is 6.9 (Medium).
Operationally, ranked in the top 46.8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-34858
Vulnerability details
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination…
more
IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
- CWE(s)
- KEV Date Added
- 09 June 2026
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Insufficient information to map techniques.Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.