boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-7473MEDIUM
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    6.9   .0111   63.3   YES
AFFECTED
  Product  Versions  Fixed
  EOS      4.36.0 –  —
TIMELINE
  Apr 29  Reserved by Arista
  Jun 9   Added to CISA KEV, remediation due 2026-06-23
  Jun 9   Published (CNA: Arista)
  Jun 24  DUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog.
CWE-1023 · CNA: Arista · CVSS v4.0 · 3 references · NVD status: Analyzed · KEV due June 23, 2026

Description

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
April 29, 2026ReservedReserved by Arista
June 9, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-06-23
June 9, 2026PublishedPublished (CNA: Arista)
June 24, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Arista NetworksEOS4.36.0

Weaknesses

CWE-1023

References (3)

Related

Authoritative record: CVE-2026-7473 at cve.org

Vendors: arista networks

Weaknesses: CWE-1023

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-7473 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.