HOMEVULNERABILITIESCVE-2026-7473
MEDIUMCISA KEVIN THE WILD

CVE-2026-7473

CWE-1023Published: June 5, 2026· Updated: Jun 17, 2026

5.8
CVSS v3.1
EPSS:0.03%probability of exploitation in 30 daysPercentile:8.6th

Official Description

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.

This issue has been reported as being exploited in the wild.

NVD Source

Risk Analysis

This medium-severity vulnerability in Arista EOS allows a switch to incorrectly decapsulate and forward unexpected tunneled packets. With a CVSS score of 5.8, this flaw can lead to unintended network traffic processing and potential information leakage. It is confirmed to be actively exploited, indicating a need for prompt attention.

This issue has been reported as being exploited in the wild. It is remotely exploitable over the network with low attack complexity and requires no authentication.

Recommended Action

Review and adjust tunnel decapsulation configurations on Arista EOS devices. Ensure proper validation of tunnel protocol types to prevent unexpected traffic processing.

Generated by the CTIWATCH analysis pipeline from this CVE's metadata (CVSS, EPSS, KEV status, exploit intelligence). Verify against vendor advisories before acting.

Technical Analysis

CVE-2026-7473 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.

CISA has added CVE-2026-7473 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeChanged
Impact
ConfidentialityNone
IntegrityLow
AvailabilityNone
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Affected Vendors & Products

arista102 product(s)
eos7020sr-24c27020sr-32c27020srg-24c27020tr-487020tra-487280cr-487280cr2-607280cr2a-307280cr2a-607280cr2k-307280cr2k-60+90
Source: NVD CPE · 102 total CPE entries

Exploit & PoC Resources

ACTIVE EXPLOITATIONConfirmed exploitation in the wild
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

News & Research Mentioning CVE-2026-7473

CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA Alerts· Jun 9, 2026

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures ( [xlite_meta score:54 src:CISA Alerts xlite_fp:f5c925405934f523e4a00a031732375aef6b8c3a722c3a629bc6338d0c644fc3]

All References (3)

Quick Facts

CVE IDCVE-2026-7473
CVSS Score5.8 / 10
SeverityMEDIUM
WeaknessCWE-1023
CISA KEVYES — Active Exploitation
ExploitIN THE WILD
EPSS (30d)0.03%
Affected1 vendor(s)
PublishedJun 5, 2026

Related CVEs (CWE-1023)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-7473 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
  • !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
  • !Active exploitation confirmed — treat as P1
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.