CyberRota
← Ana sayfaya dön

CVE-2026-7473

MEDIUM · CVSS 5.8 EPSS %0.84 CISA KEV · Aktif istismar Public Exploit

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-05T17:17:02.850 · Çekilme zamanı: 2026-06-30T12:11:34.547176+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

Public Exploit Sinyali

Bu CVE için açıklama veya referanslarda public exploit / PoC / GitHub / Metasploit sinyali tespit edildi.

Tespit Edilen Sinyaller
exploit

Not: Bu bağlantılar yalnızca güvenlik araştırması ve doğrulama amacıyla listelenmiştir.

CISA KEV Bilgisi

Durum: Bu CVE, sahada aktif istismar edilmiş açıklar katalogunda yer alıyor.

Ransomware Kullanımı: Unknown

KEV Eklenme Tarihi: 2026-06-09

Önerilen Aksiyon: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE
CVE-2026-7473
Severity
MEDIUM
CVSS
5.8
EPSS
%0.84

Orijinal NVD Açıklaması

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.