Vulnerabilities
Vulnerable Software
Arista:  >> Eos  >> 4.24.11m  Security Vulnerabilities
CVE-2026-7473
Known exploited
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
CVSS Score
6.9
EPSS Score
0.011
Published
2026-06-05
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place.
CVSS Score
5.3
EPSS Score
0.005
Published
2023-08-29
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
CVSS Score
7.5
EPSS Score
0.006
Published
2023-06-05


Contact Us

Shodan ® - All rights reserved