Impact
A vulnerability in Arista EOS causes the switch to incorrectly decapsulate packets whose destination IP matches a configured decapsulation IP, regardless of the tunnel protocol. The device does not verify the tunnel protocol type, so unexpected tunneled traffic is silently removed and forwarded as normal routing traffic. This flaw, identified as CWE‑1023, can lead to misrouting, policy violations, and unintended exposure of traffic, affecting confidentiality, integrity, and availability within the network.
Affected Systems
All Arista EOS platforms that have a tunnel decapsulation configuration, including the 7020R, 7280R, 7500R, and 7800R series, as well as other EOS releases that support VXLAN, GRE, or IP‑in‑IP decapsulation.
Risk and Exploitability
The CVSS score of 6.9 places the vulnerability in the moderate range, while an EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is listed in the CISA KEV catalog, confirming that it has been exploited in the wild. There is no software upgrade path planned to address this issue; the recommended resolution is to adopt the CNA‑recommended ACL‑based workaround. The likely attack vector is network‑layer; an adversary can send crafted tunneled packets to the switch’s decapsulation IP, causing the device to accept and forward traffic it was not intended to handle.
OpenCVE Enrichment