Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2026-7473


On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 5.8, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts limited integrity, for affected systems. Impacting 102 products from arista, from arista, from arista and 99 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2026, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2026-06-05T17:17:02.850

Last Modified

2026-06-17T11:02:29.070

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-1023

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System arista eos * Yes
Hardware arista 7020sr-24c2 - No
Hardware arista 7020sr-32c2 - No
Hardware arista 7020srg-24c2 - No
Hardware arista 7020tr-48 - No
Hardware arista 7020tra-48 - No
Hardware arista 7280cr-48 - No
Hardware arista 7280cr2-60 - No
Hardware arista 7280cr2a-30 - No
Hardware arista 7280cr2a-60 - No
Hardware arista 7280cr2k-30 - No
Hardware arista 7280cr2k-60 - No
Hardware arista 7280cr2m-30 - No
Hardware arista 7280cr3-32d4 - No
Hardware arista 7280cr3-32p4 - No
Hardware arista 7280cr3-36s - No
Hardware arista 7280cr3-96 - No
Hardware arista 7280cr3a-24d12 - No
Hardware arista 7280cr3a-48d6 - No
Hardware arista 7280cr3a-72 - No
Hardware arista 7280cr3ak-24d12 - No
Hardware arista 7280cr3ak-48d6 - No
Hardware arista 7280cr3ak-72 - No
Hardware arista 7280cr3am-24d12 - No
Hardware arista 7280cr3am-48d6 - No
Hardware arista 7280cr3am-72 - No
Hardware arista 7280cr3mk-32d4s - No
Hardware arista 7280cr3mk-32p4s - No
Hardware arista 7280dr3-24 - No
Hardware arista 7280dr3a-36 - No
Hardware arista 7280dr3a-54 - No
Hardware arista 7280dr3ak-36 - No
Hardware arista 7280dr3ak-54 - No
Hardware arista 7280dr3am-36 - No
Hardware arista 7280dr3am-54 - No
Hardware arista 7280pr3-24 - No
Hardware arista 7280qr-c36 - No
Hardware arista 7280qr-c36-m - No
Hardware arista 7280qr-c72 - No
Hardware arista 7280qra-c36s - No
Hardware arista 7280qra-c36sm - No
Hardware arista 7280sr-48c6 - No
Hardware arista 7280sr2-48yc6 - No
Hardware arista 7280sr2-48yc6-m - No
Hardware arista 7280sr2a-48yc6 - No
Hardware arista 7280sr2a-48yc6-m - No
Hardware arista 7280sr2k-48c6-m - No
Hardware arista 7280sr3-40yc6 - No
Hardware arista 7280sr3-48yc8 - No
Hardware arista 7280sr3m-48yc8 - No
Hardware arista 7280sra-48c6 - No
Hardware arista 7280sra-48c6-m - No
Hardware arista 7280sram-48c6 - No
Hardware arista 7280srm-40cx2 - No
Hardware arista 7280tr-48c6 - No
Hardware arista 7280tr3-40c6 - No
Hardware arista 7280tra-48c6 - No
Hardware arista 7280tra-48c6-m - No
Hardware arista 7289r3a-sc - No
Hardware arista 7289r3ak-sc - No
Hardware arista 7289r3am-sc - No
Hardware arista 7500r-36cq-lc - No
Hardware arista 7500r-36q-lc - No
Hardware arista 7500r-48s2cq-lc - No
Hardware arista 7500r-8cfpx-lc - No
Hardware arista 7500r2-36cq-lc - No
Hardware arista 7500r2a-36cq-lc - No
Hardware arista 7500r2ak-36cq-lc - No
Hardware arista 7500r2ak-48ycq-lc - No
Hardware arista 7500r2am-36cq-lc - No
Hardware arista 7500r2m-36cq-lc - No
Hardware arista 7500r3-24d - No
Hardware arista 7500r3-24p - No
Hardware arista 7500r3-36cq - No
Hardware arista 7500r3k-36cq - No
Hardware arista 7500r3k-48y4d - No
Hardware arista 7500rm-36cq-lc - No
Hardware arista 7504r-fm - No
Hardware arista 7504r3 - No
Hardware arista 7508r-fm - No
Hardware arista 7508r3 - No
Hardware arista 7512r-fm - No
Hardware arista 7512r3 - No
Hardware arista 7516-sup2 - No
Hardware arista 7516n-ch - No
Hardware arista 7516r-fm - No
Hardware arista 7800r3-36d - No
Hardware arista 7800r3-48cq - No
Hardware arista 7800r3a-36d - No
Hardware arista 7800r3a-36dm - No
Hardware arista 7800r3a-36p - No
Hardware arista 7800r3a-36pm - No
Hardware arista 7800r3ak-36dm - No
Hardware arista 7800r3ak-36pm - No
Hardware arista 7800r3k-48cq - No
Hardware arista 7800r3k-48cqms - No
Hardware arista 7800r3k-72y - No
Hardware arista 7804r3 - No
Hardware arista 7808r3 - No
Hardware arista 7812r3 - No
Hardware arista 7816lr3 - No
Hardware arista 7816r3 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For arista's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.