Vulnerabilities
Vulnerable Software
Arista:  >> 7020tr-48  Security Vulnerabilities
CVE-2026-7473
Known exploited
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
CVSS Score
6.9
EPSS Score
0.004
Published
2026-06-05
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
CVSS Score
7.5
EPSS Score
0.006
Published
2023-06-05
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision
CVSS Score
8.8
EPSS Score
0.006
Published
2023-04-25
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulnerability does not have any confidentiality or integrity impacts to the system.
CVSS Score
5.3
EPSS Score
0.008
Published
2023-04-12


Contact Us

Shodan ® - All rights reserved