ZeroHour

CVE-2026-7473

KEVlarge

Incomplete Tunnel Protocol Verification in Arista EOS Exploited in the Wild

CISA: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

CVSS 4.0
6.9 medium
EPSS
1%p64
Published
()
KEV added
AI analysis

Arista EOS switches configured for tunnel decapsulation — VXLAN, decap-groups, or a GRE tunnel interface — fail to verify the tunnel protocol type of incoming packets before decapsulating them (CWE-1023, incomplete comparison with missing factors). An attacker can send an unexpected type of tunneled packet whose destination IP matches the switch's configured decapsulation IP, causing the switch to incorrectly decapsulate and forward it as if it belonged to the configured tunnel. The result is a traffic-integrity problem — packets are processed and delivered through a path they were never intended for — reflected in the CVSS 4.0 score of 6.9 as network-triggered, unauthenticated, integrity-only impact with no confidentiality or availability loss. Only deployments running Arista EOS with a tunnel decapsulation configuration are affected; sites without VXLAN/decap-group/GRE decapsulation are not exposed to this flaw. Exploitation in the wild has been reported — CISA added the issue to the Known Exploited Vulnerabilities catalog on 2026-06-09 — though no public proof-of-concept is known and ransomware use has not been confirmed.

What to do: Inventory Arista EOS devices for tunnel decapsulation configuration (VXLAN, decap-groups, or GRE tunnel interfaces) and check whether the configured decapsulation IP is reachable from untrusted networks. Upgrade to a fixed EOS release per Arista's advisory for CVE-2026-7473 (fixed versions are not specified in the available data) or apply the vendor's recommended mitigation, such as filtering unexpected tunnel traffic destined to the decapsulation IP; federal agencies must remediate within the BOD 22-01 timeline following the 2026-06-09 KEV addition. Because the scored impact is limited to traffic-handling integrity, prioritize the exposure assessment, but do not defer patching given confirmed in-the-wild exploitation.

Affected
Arista EOS (Extensible Operating System)
Estimated exposure
large≈tens of thousands to ~100,000 systems/sites (VXLAN decap-groups and GRE decapsulation are common configurations in Arista data-center fabrics) — Arista is a leading data-center switching vendor with a cumulative EOS installed base publicly estimated in the hundreds of thousands of switches, and VXLAN/decap-group or GRE tunnel decapsulation is a routine configuration in those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

CISA Known Exploited Vulnerability
Affected
Arista Extensible Operating System
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
arista
Products
eos
Weakness
CWE-1023
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news