CISA KEV · catalog date Jun 9, 2026 · first observed Jul 19, 2026
Evidence dossier
CVE-2026-7473
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
Exploited in the wild (CISA KEV since Jun 9, 2026). Arista reports CVSS 4.0 6.9. EPSS estimates 1.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
- State
- PUBLISHED
- Published
- Jun 5, 2026
- Updated
- Jun 10, 2026
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAAristaOriginal evidence ↗
Record text: Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
Inspect raw assertion
- Field
container- Value
- Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 1.11% probability · 63.47th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.011080000000; percentile 0.634700000000
FIRST EPSS · score date Aug 27, 2026 · 63.5th percentile · first observed Aug 27, 2026
Arista · CVSS 4.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
Inspect raw assertion
- Field
container- Value
- Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
1.11% probability · 63.47th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.011080000000; percentile 0.634700000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
103 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.36.0", "versionType": "custom"}, {"status": "affected", "version": "4.35.0", "versionType": "custom", "lessThanOrEqual": "4.35"}, {"status": "affected", "version": "4.34.0", "versionType": "custom", "lessThanOrEqual": "4.34"}, {"status": "affected", "version": "4.33.0", "versionType": "custom", "lessThanOrEqual": "4.33"}, {"status": "affected", "version": "4.32.0", "versionType": "custom", "lessThanOrEqual": "4.32"}, {"status": "affected", "version": "4.31.0", "versionType": "custom", "lessThanOrEqual": "4.31"}, {"status": "affected", "version": "*", "versionType": "custom", "lessThanOrEqual": "4.30"}]product-30406eec637a8ed821401c11fefb178538b84aaca3af0546149a190857b3d887Linked exactInspect raw assertion
cpe:2.3:h:arista:7020sr-24c2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7781cb15-3452-47d9-a961-8b09f2e9aec1
product-b14909d599d0db549ca189a22e83b605ea6a282108592b830b79c51a9cb7d306Linked exactInspect raw assertion
cpe:2.3:h:arista:7020sr-32c2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
09a31fb8-512e-43ef-8f87-e02e35f5251e
product-ddf105e01294b2cb4168c1b00e01f396de0b5c91ea93caee28e4fbaacff58aacLinked exactInspect raw assertion
cpe:2.3:h:arista:7020srg-24c2:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
282ff2e7-cddc-4f32-89c9-4c79b7518e0e
product-ebcdf17b688cbe30fd9859a52973402f8a610b125948912169ed4225dfb7291dLinked exactInspect raw assertion
cpe:2.3:h:arista:7020tr-48:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2cbff922-28d7-42d6-8796-91ad9a178d28
product-fef246f6f27b01bc0027401e724758f90b39b8c243ac3ae174c6f8c53d7582adLinked exactInspect raw assertion
cpe:2.3:h:arista:7020tra-48:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
561b4042-dfd3-4bc0-9c5f-74799a7e92c5
product-a429b19482a57900ec6658c0c334d27bfddcc6229eed2d7b9375a193e4aa8712Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr2-60:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cc31ef21-07c9-485e-8364-9bd7c65af428
product-ff50b06ffe6fb35fc260c18047bc4bc9da71a87e41e064208405fc8bf256f8c1Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr2a-30:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c8355e97-0cbe-4e3e-ae22-3c859fa284b6
product-1e3f5ca481660656969cc2ec0a31a2a3c7b8008e8de76dad75d6f4c7e21eec0eLinked exactInspect raw assertion
cpe:2.3:h:arista:7280cr2a-60:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a47e990a-1751-4a5f-8a0a-8b9c8ad3662d
product-038ff98ff64578c364f6e3f1aaba7c8b9263ad4e6fe0c16c9ba3fdfda76aa96fLinked exactInspect raw assertion
cpe:2.3:h:arista:7280cr2k-30:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
376d7f0c-57e5-416f-a376-698a1a90f1cd
product-d01e0edab87d9a22f94468e08144bd0c5d3a9f767d8c360ad3269b78eaeb4522Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr2k-60:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f569286-c19f-48cb-ab24-89c4a1eb6f81
product-b132b0c363abdc4875afdc31c7f4a0d83b69273530ac3bff4db01fb322ab7e52Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr2m-30:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e03ae8c4-f3f2-4c2c-bfc5-3fa31823ec8f
product-887e8eeab78c2a8bdfac221e92eddf07c373b25ad831dfecdf4810ff05ab962dLinked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3-32d4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7fec18b3-7980-4ebf-8e15-f8e92dadd062
product-55f6f0e2a5339195ee4a1ee2ae0ae1a37749b49272015e98158aaae4e3d2af73Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3-32p4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
87e85f7c-f33b-49c1-a526-acc1bef3b65c
product-f756b51b15d405ae8a1466d554fff4b5f7c4dc4adaab6ca18a61c11731fc2eb7Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3-36s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a3b9cb1b-730e-45c9-a0b1-3c2f4a72a159
product-a298596ecaaa3b754c8a401b3154ed4875c8b98fcaa69ba7afb0513a0d5425b7Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3-96:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2e54f451-ca87-4f32-a088-ae18123ce07a
product-d163c7b13461c17b8bcc21e2d7e4648fe62ed82d3b0cfdc599f89bad78d27779Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3a-24d12:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
43b967ed-2212-4558-a9ac-aca94c94fd39
product-3615fb827d938ee01b7015dfcf59cbde9d020ebc613a6f13b860da0fbe908ccaLinked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3a-48d6:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd7877c6-9de4-4952-94d2-3a456d02cf1a
product-bb6698998634ffbcae27f1af00f9e815d6bf77411aa6b743705a3f96befab61eLinked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3a-72:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2fd635fb-5ea8-4b02-894c-4c016090aab3
product-4b40819e55414411c4c64607ae1b545e466133645082fee7baf69949abea18f0Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3ak-24d12:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f567fcb9-80b3-4580-9181-6f2ffeddec12
product-f782043fbda09f6fac6dd40c773a7f720f16ac62f68e252d0e63d520a10135e1Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3ak-48d6:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d184ba0-02cb-4323-9d44-b02ad32067af
product-c595d2d5b5076e9a4c3f88cc8308ad7933a429279a35e47cb3b24e1dfbad6bd6Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3ak-72:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4627ca2-6b54-4588-9f4b-7f19dd0e0c2e
product-dc8cb0c29e5408bd7c80114102cfdb9c255e7695ae321c43486895acd3b48f73Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3am-24d12:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
537aac04-2ca2-46e2-aae0-381615604b38
product-780387ee7936589d2c3c40ea4614e36586b47aecbfbe2500e7bb3101e8a15cd9Linked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3am-48d6:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b08d43de-ad41-41de-89d8-db0ea9b10637
product-abaa608105268b219c778adecb68ef9fd09c8fe312fc7334391afec9c71d83beLinked exactInspect raw assertion
cpe:2.3:h:arista:7280cr3am-72:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5f879845-50b7-4202-8831-52cb903d2c8c
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-7e10c48e52fcf2817914dceb8275ea9f4e9fa821be3da90f14277e3dfb509042 · product-4a9e5f8d20063f77280080e593816b0a266f41ffdabcb0171c11eeb4f7f06280
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3214a35e-3c14-4422-b992-aa54e215bdb9Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6929ce34-1ccc-4260-beb2-7ac2b7cbf677Assessments
CVSS by origin
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:NCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:NDirect CVE/CNA normalized decisions
Arista
CVSS 4.0 · Primary · Original assertion · rank 1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N- Validation
- Valid match
- Recomputed
- 6.9
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Arista
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N- Validation
- Valid match
- Recomputed
- 5.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.