Knox CVE Database
/
CVE-2026-7473
Medium
6.9

CVE-2026-7473: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

Added to the CISA KEV catalog:
June 9, 2026

Overview

Arista EOS switches configured as tunnel decapsulation endpoints contain a flaw in how they validate incoming tunneled traffic. The switch checks only whether a packet's destination IP matches its configured decapsulation address, but does not verify the tunnel protocol type. An attacker who can reach that IP can send packets using a non-configured tunnel protocol and the switch will decapsulate and forward them, injecting traffic into the network segment behind the endpoint. Affected hardware includes the 7020R, 7280R/R2, and 7500R/R2 series, with limited exposure on R3 variants. This vulnerability has been confirmed exploited in the wild.

Vulnerability details

Affected vendor
Arista
Affected product
Extensible Operating System
Weakness type (CWE)
CWE-1023

CWE-1023 describes a comparison that omits a necessary factor. In Arista EOS, the tunnel decapsulation path checks the destination IP of an incoming packet against the configured decapsulation address but performs no corresponding check on the encapsulation protocol. A switch configured for VXLAN, GRE, or a decap-group will therefore accept and process packets using any other tunnel protocol that shares the same destination IP, because the protocol-type factor is simply absent from the admission check.


An attacker who can send network packets to the switch's configured decapsulation IP crafts a tunneled packet using a protocol the switch was not configured to handle, such as GRE sent to a VXLAN VTEP or IPoIP sent to a GRE endpoint. The switch decapsulates the packet and forwards the inner payload into the network segment behind the tunnel endpoint, achieving unauthorized packet injection. Some combinations require additional switch configuration to be present, such as a matching VXLAN VNI or GUE decap-group, but the core precondition is simply network reachability to the decapsulation IP.

Severity and impact

6.9
Medium
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Confidentiality impact
None
Integrity impact
Low
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor tunnel-facing interfaces for encapsulated traffic whose outer protocol does not match the configured tunnel type on that interface. For example, GRE-encapsulated frames arriving on a VXLAN-only VTEP IP, or IPoIP frames arriving on a GRE decap-group address, indicate unexpected decapsulation activity.
  • Inspect forwarded traffic originating from the tunnel decapsulation IP for inner-payload sources that do not belong to any configured tunnel peer list. Traffic forwarded into the internal segment from an unrecognized outer-protocol source is a concrete indicator of exploitation.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 23, 2026

Additional hardening

  • Upgrade affected EOS releases on 7020R, 7280R/R2, and 7500R/R2 hardware to a fixed release per the Arista Security Advisory 0137; consult the vendor advisory listed in References for exact fixed-version boundaries per release train.
  • Apply inbound ACLs on decapsulation interfaces to permit only the specific tunnel protocol and source IPs that are explicitly configured, dropping all other encapsulated traffic destined to the decapsulation IP. The vendor advisory includes a caution note on ACL application; review it before deploying.
  • Restrict network reachability to the decapsulation IP to known tunnel peers only, using upstream firewall rules or router ACLs, reducing the attacker's ability to reach the vulnerable endpoint from arbitrary sources.
  • Audit all tunnel decapsulation configurations across the fleet and remove any VXLAN VTEP, GRE tunnel interface, or ip decap-group entries that are no longer operationally required, shrinking the exposed attack surface.

Key dates

Published (NVD)
June 5, 2026
Added to CISA KEV
June 9, 2026
Remediation deadline
June 23, 2026
Last updated
June 17, 2026

References

Frequently asked questions

Does CVE-2026-7473 affect my FedRAMP authorization?

If Arista Extensible Operating System runs inside your authorization boundary, yes. CVE-2026-7473 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its June 23, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV is a finding your assessor and sponsoring agency can see. At this point, the finding is overdue: you remediate it now or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-7473?

Knox does not patch your software. Remediating Arista Extensible Operating System is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-7473. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-7473's remediation deadline of June 23, 2026 has passed. What happens now?

If CVE-2026-7473 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding out and documenting why the deadline was missed is what keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting