قاعدة الثغرات (CVE)
CVE-2026-7473
مقارنة ناقصة تسمح بتمرير حزم نفقية غير متوقعة في Arista EOS
خلل في مقارنة الحزم يجعل المبدّل يفك تغليف حزم نفقية غير متوقعة ويعيد توجيهها، ما يتيح تجاوز عزل الشبكة.
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| Extensible Operating System | — | — |
التغطية على سيبرانا
—