$ intel.mask2.ca

ADVISORY · 2026-06-11 · SRC CISA-KEV · MEDIUM
2026-06-11 medium REL 6/10

Arista EOS Packet Decapsulation Vulnerability Could Enable Network Spoofing

energyhealthcaregovernmentfinance

Arista Extensible Operating System contains a flaw in packet decapsulation logic that may allow attackers to forward specially crafted tunneled packets by exploiting incomplete validation. The vulnerability affects network switches and requires vendor mitigations or product discontinuation. CISA has added this to the Known Exploited Vulnerabilities catalog with a June 2026 remediation deadline.

Why it matters in Western Canada: Energy, healthcare, and government organizations across Western Canada rely on Arista networking infrastructure for critical operations. Exploitation could compromise network segmentation and enable lateral movement within sensitive environments.

CVEs: CVE-2026-7473


Summary generated from the original advisory. Read the full source: cisa-kev

Source
https://nvd.nist.gov/vuln/detail/CVE-2026-7473
CVEs
CVE-2026-7473
Tags
network, arista, packet-forwarding, infrastructure, kev-catalog
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)