{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-7473",
  "revision": 1,
  "title": "Arista EOS — tunnel decapsulation without a protocol check",
  "summary": "Arista's switch operating system (EOS) unwraps tunnelled packets aimed at its tunnel address without checking that the tunnel protocol is the one configured, so unrelated tunnelled traffic is decapsulated and forwarded into the network.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 6.9,
    "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
    "version": "4.0"
  },
  "epss": 0.01108,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-06-09",
    "prerequisites": "Ability to send tunnelled packets to the switch's configured decapsulation address."
  },
  "remediation": {
    "workaround_available": true
  },
  "kill_chain": "defense_evasion",
  "recommended_action": "Apply the fix or the mitigation in Arista Security Advisory 0137 now; audit which decapsulation addresses are configured and restrict who can reach them.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-7473",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-7473",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-7473",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7473",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137"
    }
  ],
  "published_at": "2026-06-05T17:17:02.850Z",
  "issued_at": "2026-09-24T06:28:59.498Z",
  "tags": [
    "arista",
    "eos",
    "network",
    "tunnel",
    "segmentation-bypass",
    "kev"
  ]
}
