ctipilot.ch

Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited

cve · CVE-2026-7473 single-source

Coverage timeline
1
first 2026-06-10 → last 2026-06-25
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Defense Impairment TA0112

T1599.001Network Boundary Bridging: Network Address Translation Traversal×1

Adversaries may bridge network boundaries by modifying a network device’s Network Address Translation (NAT) configuration. Malicious modifications to NAT may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks.

Evidence: 2026-06-10/cve-2026-7473-arista-eos-tunnel-decapsulation-logic-flaw-byp · ATT&CK page ↗

Story timeline

  1. 2026-06-10CVE-2026-7473 — Arista EOS tunnel-decapsulation logic flaw bypasses segmentation, added to CISA KEV
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • arista.com1 (100%)

explore in graph

Entries about Arista EOS tunnel-decapsulation logic flaw (CWE-1023) bypasses VXLAN segmentation; CISA KEV, exploited (1)

2026-06-10 · view entry permalink →

NOTABLECVE-2026-7473exploited

CVE-2026-7473 — Arista EOS tunnel-decapsulation logic flaw bypasses segmentation, added to CISA KEV

Arista EOS contains an incomplete-comparison flaw (CWE-1023) in its tunnel-decapsulation logic: where a VXLAN, decap-group or GRE decapsulation config is present, the switch decapsulates and forwards tunneled packets whose destination IP matches the configured decap IP even from unexpected sources, letting an attacker inject traffic into a VXLAN fabric and bypass network segmentation; CISA added CVE-2026-7473 to its KEV catalog on 9 June (Arista, 2026-06-09). Relevant to datacenter-fabric operators in CH/EU finance and government. Apply Arista SA-0137 and add decap source-IP validation/access-lists on VTEP interfaces (T1599.001).

Arista EOS contains an incomplete-comparison flaw (CWE-1023) in its tunnel-decapsulation logic: where a VXLAN, decap-group or GRE decapsulation config is present, the switch decapsulates and forwards tunneled packets whose destination IP matches the configured decap IP even from unexpected sources …

ctipilot v2 brief (migrated)
vulnerability10 Jun 05:00Zsingle-sourceOpen finding ↗