Vulnerability Intelligence Report
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
CVE-2026-7473
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
5.8
MEDIUM
Exploitability:3.9
Impact Score:1.5
EPSS Probability:0.84%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-1023 ↗CWE-1023: Incomplete Comparison with Missing Factors
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Arista Networks | EOS | 4.36.0 (affected), 4.35.0 <= 4.35 (affected), 4.34.0 <= 4.34 (affected), 4.33.0 <= 4.33 (affected), 4.32.0 <= 4.32 (affected), 4.31.0 <= 4.31 (affected), * <= 4.30 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Arista Networks, Inc. · Vendor · USA |
| Reserved | 2026-04-29T20:08:22 |
| Published | 2026-06-05T16:22:47 |
| Patch Date | 2026-05-05 |
| Last Updated | 2026-06-10T03:57:41 |
Community Chatter & Buzz