ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-7473

CRITICAL Export PDF

Arista Extensible Operating System Vulnerability

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

CVSS Score
9.8
CRITICAL
Published
09 Jun 2026 00:00
Modified
N/A
Vendor
Arista
Product
Extensible Operating System
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-1023

Affected Systems

Arista
Extensible Operating System
Arista
VeloCloud Orchestrator
Extensible Operating System

KEV Status

Known Exploited Vulnerability