Executive brief
Arista network switches running EOS may incorrectly process and forward network traffic that uses unauthorized tunneling protocols. This occurs when the device is configured for specific types of network virtualization (like VXLAN or GRE) but fails to verify if incoming traffic matches the expected protocol. An attacker could exploit this to bypass certain network traffic controls or inject unexpected data into the network, and there are reports that this vulnerability is being actively exploited.
Technical details
Arista EOS platforms configured with tunnel decapsulation (such as VXLAN, GRE, or decap-groups) fail to properly verify the tunnel protocol type of incoming packets. If a packet's destination IP matches a configured decapsulation IP, the switch may incorrectly decapsulate and forward the payload even if it uses a non-configured or unexpected tunnel protocol. This vulnerability, classified as CWE-1023 (Incomplete Comparison with Missing Factors), allows for the processing of unauthorized tunnel traffic. The issue is reachable over the network without authentication and has been reported as exploited in the wild.
Affected products
- Arista Extensible Operating System (EOS)
Timeline
- 2026-06-05: advisory: Initial publication by Arista Networks
- 2026-06-05: exploited: Reported as being exploited in the wild at time of disclosure