Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Arista EOS switches configured as tunnel decapsulation endpoints contain a flaw in how they validate incoming tunneled traffic. The switch checks only whether a packet's destination IP matches its configured decapsulation address, but does not verify the tunnel protocol type. An attacker who can reach that IP can send packets using a non-configured tunnel protocol and the switch will decapsulate and forward them, injecting traffic into the network segment behind the endpoint. Affected hardware includes the 7020R, 7280R/R2, and 7500R/R2 series, with limited exposure on R3 variants. This vulnerability has been confirmed exploited in the wild.
CWE-1023 describes a comparison that omits a necessary factor. In Arista EOS, the tunnel decapsulation path checks the destination IP of an incoming packet against the configured decapsulation address but performs no corresponding check on the encapsulation protocol. A switch configured for VXLAN, GRE, or a decap-group will therefore accept and process packets using any other tunnel protocol that shares the same destination IP, because the protocol-type factor is simply absent from the admission check.
An attacker who can send network packets to the switch's configured decapsulation IP crafts a tunneled packet using a protocol the switch was not configured to handle, such as GRE sent to a VXLAN VTEP or IPoIP sent to a GRE endpoint. The switch decapsulates the packet and forwards the inner payload into the network segment behind the tunnel endpoint, achieving unauthorized packet injection. Some combinations require additional switch configuration to be present, such as a matching VXLAN VNI or GUE decap-group, but the core precondition is simply network reachability to the decapsulation IP.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Arista Extensible Operating System runs inside your authorization boundary, yes. CVE-2026-7473 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its June 23, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV is a finding your assessor and sponsoring agency can see. At this point, the finding is overdue: you remediate it now or formally document the mitigation and the delay.
Knox does not patch your software. Remediating Arista Extensible Operating System is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.
Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-7473. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-7473 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









