Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3198 articles · 183323 vulns · 37/41 feeds (7d)
← Back to list
5.8
CVE-2026-7473KEVEXPLOITEDPATCHED
arista · eos

Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass

Description

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

Affected Products

VendorProductVersions
aristaeos4.36.0, 4.35.0, 4.34.0, 4.33.0, 4.32.0, 4.31.0, *

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arista7280cr3-36scve_cpe95%
arista7020sr-24c2cve_cpe95%
arista7020sr-32c2cve_cpe95%
arista7020srg-24c2cve_cpe95%
arista7020tr-48cve_cpe95%

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137(vendor-advisory)

Related News (1 articles)

Tier C
VulDB58d ago
CVE-2026-7473 | Arista EOS up to 4.36.0 Configuration incomplete comparison with missing factors
→ No new info (linked only)
CVSS 3.15.8 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://www.arista.com/en/support/advisories-notices/security-advisory/22872-security-advisory-0137
CWECWE-1023
PublishedJun 5, 2026
Last enriched58d ago
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16812
VeloCloud Orchestrator OS Command Injection
Trending: 82
NONECVE-2024-27891EXP
On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.
NONECVE-2023-5502EXP
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.
HIGHCVE-2025-8873EXP
Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
HIGHCVE-2025-5088
Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 5, 2026
Added to CISA KEV
Jun 5, 2026
Discovered by ZDM
Jun 5, 2026
Actively Exploited
Jun 10, 2026
Patch Available
Jun 10, 2026