CVE-2026-7473: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Other sources
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic.
This issue has been reported as being exploited in the wild.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Arista Extensible Operating System (EOS)from your environment.Discontinue use of the product if vendor mitigations are unavailable or cannot be applied safely; remove or take affected devices running Arista EOS out of service until mitigations or other safe controls are in place.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services. Apply the workaround/mitigation steps provided by Arista for affected platforms with tunnel decapsulation configurations (for example VXLAN, decap-groups, or GRE) to prevent unexpected decapsulation and forwarding of tunneled packets.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7473?
The severity of CVE-2026-7473 is rated medium with a score of 5.8.
How does CVE-2026-7473 affect Arista EOS?
CVE-2026-7473 affects Arista EOS by causing it to unexpectedly decapsulate and forward tunneled packets, potentially leading to data exposure.
How do I fix CVE-2026-7473?
There is no software upgrade path for CVE-2026-7473; follow the recommended mitigation instructions provided in the workaround section.
What types of tunnel configurations are impacted by CVE-2026-7473?
CVE-2026-7473 impacts tunnel configurations such as VXLAN, decap-groups, and GRE tunnel interfaces.
Is there a workaround for CVE-2026-7473?
Yes, the recommended resolution for CVE-2026-7473 is to implement the appropriate mitigation instructions as detailed in the advisory.