{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 137 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137"
      }
    ],
    "title": "Security Advisory 137",
    "tracking": {
      "current_release_date": "2026-07-28T19:58:28Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 137",
      "initial_release_date": "2026-07-28T19:58:28Z",
      "revision_history": [
        {
          "date": "2026-07-28T19:58:28Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 1.0.0",
                    "product": {
                      "name": "EOS version 1.0.0",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-7473",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1086442,1519884"
      },
      "notes": [
        {
          "category": "description",
          "text": "When an IP tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), IP decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch might incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching the configured decapsulation IP.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "This issue could be seen when one of the following tunnel decapsulation configurations is present:\n* VXLAN (Virtual Extensible LAN) Tunnel Interface\n* IP decap-group\n* GRE (Generic Routing Encapsulation) tunnel interface",
          "title": "1086442: Required Config for Exploitation"
        },
        {
          "category": "other",
          "text": "This issue could be seen when one of the following IPv6 tunnel decapsulation configurations is present:\n* IP-in-IPv6 Decap Group\n* GUEv6 Decap Group",
          "title": "1519884: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-0"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7473"
        },
        {
          "category": "external",
          "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137"
        }
      ],
      "remediations": [
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "mitigation",
          "details": "There are two broad approaches to mitigate this issue - (1) applying ACLs on upstream devices or (2) applying ACLs on the devices where the unexpected decapsulation is happening. In both cases, the idea is to either selectively allow only legitimate tunnel traffic or to selectively block malicious tunnel traffic. For example, if a network is configured to forward VXLAN traffic, but GRE traffic is being unexpectedly forwarded, then ACLs can be used to either selectively allow just VXLAN traffic or selectively block GRE traffic."
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "mitigation",
          "details": "There are two broad approaches to mitigate this issue - (1) applying ACLs on upstream devices or (2) applying ACLs on the devices where the unexpected decapsulation is happening. In both cases, the idea is to either selectively allow only legitimate tunnel traffic or to selectively block malicious tunnel traffic. For example, if a network is configured to forward GUEv6 traffic, but GREv6 traffic is being unexpectedly forwarded, then ACLs can be used to either selectively allow just GUEv6 traffic or selectively block GREv6 traffic."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0"
          ]
        }
      ],
      "title": "CVE-2026-7473"
    }
  ]
}