CVE-2026-7473

KEV
🔴 Łataj teraz

Błąd w Arista EOS pozwala na nieautoryzowane przetwarzanie tunelowanych pakietów.

CVSS
5.8
EPSS
27.2%
Exploit
weaponized
Vendor
arista
Opis źródłowy (NVD)

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)27.2%
Opublikowano (NVD)2026-06-05 17:17:02 UTC
Ostatnia modyfikacja (NVD)2026-06-09 20:48:49 UTC
Referencje