Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Research page generated from configured evidence sources. Treat this as an analyst workbench: facts are sourced, gaps are labelled, and low-confidence chatter is separated from confirmed evidence.
Executive judgement
- Operational lane: review now
- Priority score: 70
- Confidence: medium
- Exploit status: active — Active exploitation signal observed in configured sources.
- Urgent publishable: yes
- CISA KEV: Confirmed in CISA KEV from configured source data.
- Published/observed: 2026-06-05
- EPSS score: 0.0038 (29th percentile)
What happened
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Why it matters
- The item was promoted because the pipeline observed: priority score 70, exploit status active, confidence medium.
- It has a CVE identifier, so it can be tracked across NVD/CVE.org/vendor/exploit sources.
- No PoC signal was detected by the current pipeline unless shown elsewhere on this page.
Evidence collected
Exploitation and PoC status
- Current automated assessment: Active exploitation signal observed in configured sources.
- Public exploit/PoC: No PoC source captured yet by the configured pipeline.
- Exploited in the wild: Configured sources contain active exploitation language.
- Ransomware association: No ransomware association captured at generation time.
Publication / validation flags
- No validation flags from configured gates.
Dark web / low-confidence chatter
- No matching OTX/URLhaus/MalwareBazaar item found in configured low-confidence feeds at generation time.
- This is not proof of absence. It means the current automated sources did not capture relevant underground or malware-feed chatter.
Defender actions
- Restrict tunnel decapsulation IPs to trusted sources only
- Monitor EOS logs for unexpected decapsulated packets
- Apply Arista EOS updates per vendor advisory
Analyst note
The active exploitation and KEV listing require immediate review of Arista switch tunnel configurations. The flaw allows forwarding of unexpected packets matching the decapsulation IP. Prioritize configuration hardening and patching on exposed EOS devices.
Defender / Sentinel hunting queries
MDE exposure: devices with CVE-2026-7473
Find devices where Microsoft Defender Vulnerability Management reports the CVE.
DeviceTvmSoftwareVulnerabilities
| where CveId == "CVE-2026-7473"
| project DeviceName, OSPlatform, SoftwareVendor, SoftwareName, SoftwareVersion, VulnerabilitySeverityLevel, RecommendedSecurityUpdate, LastSeenTime
| order by VulnerabilitySeverityLevel desc, LastSeenTime desc
MDE endpoint behaviour hunt
General endpoint hunt for named tooling, malware, or exploit artefacts from the research item. Tune terms with vendor IOCs.
DeviceProcessEvents
| where Timestamp > ago(14d)
| where ProcessCommandLine has "Arista" or FileName has "Arista" or FolderPath has "Arista" or ProcessCommandLine has "Extensible" or FileName has "Extensible" or FolderPath has "Extensible" or ProcessCommandLine has "Operating" or FileName has "Operating" or FolderPath has "Operating" or ProcessCommandLine has "System" or FileName has "System" or FolderPath has "System" or ProcessCommandLine has "Incomplete" or FileName has "Incomplete" or FolderPath has "Incomplete"
| project Timestamp, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
MDE file artefact hunt
Hunt for suspicious files dropped or modified during exploitation of this vulnerability.
DeviceFileEvents
| where Timestamp > ago(14d)
| where FileName has "Arista" or FolderPath has "Arista" or InitiatingProcessCommandLine has "Arista" or FileName has "Extensible" or FolderPath has "Extensible" or InitiatingProcessCommandLine has "Extensible" or FileName has "Operating" or FolderPath has "Operating" or InitiatingProcessCommandLine has "Operating" or FileName has "System" or FolderPath has "System" or InitiatingProcessCommandLine has "System" or FileName has "Incomplete" or FolderPath has "Incomplete" or InitiatingProcessCommandLine has "Incomplete"
| project Timestamp, DeviceName, FileName, FolderPath, ActionType, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, FileSize
| order by Timestamp desc
MDE registry persistence and tamper hunt
Hunt for suspicious registry modifications (persistence, service installs, config tampering) linked to this issue.
DeviceRegistryEvents
| where Timestamp > ago(14d)
| where RegistryKey has_any ("Run", "RunOnce", "Services", "Image File Execution", "Winlogon") or RegistryValueName has "Arista" or RegistryKey has "Arista" or PreviousRegistryValueData has "Arista" or RegistryValueName has "Extensible" or RegistryKey has "Extensible" or PreviousRegistryValueData has "Extensible" or RegistryValueName has "Operating" or RegistryKey has "Operating" or PreviousRegistryValueData has "Operating" or RegistryValueName has "System" or RegistryKey has "System" or PreviousRegistryValueData has "System"
| project Timestamp, DeviceName, ActionType, RegistryKey, RegistryValueName, RegistryValueData, PreviousRegistryValueData, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc
Exposure validation ideas
- Search asset inventory for affected vendor/product names and any CVE reference.
- Check internet-facing exposure through approved tools only: Shodan/Censys/GreyNoise links below are research starting points, not proof of exposure.
- Prioritise management interfaces, edge devices, identity/control-plane systems, and OT/ICS assets where relevant.
Detection / hunting ideas
- Review vendor logs for authentication failures, privilege changes, unexpected admin activity, and anomalous management-plane access.
- Search SIEM/EDR telemetry for product-specific process names, network services, and newly published indicators from primary sources.
- Monitor for scanner traffic or nuclei/metasploit module references once public exploit tooling appears.
Research links
- NVD
- CVE.org
- CISA KEV search
- GitHub code/advisory search
- GitHub repository search
- Exploit-DB search
- Packet Storm search
- AlienVault OTX search
- GreyNoise search
- Shodan search
- Censys search
Open questions
- Is there a primary vendor advisory with exact affected versions and fixed versions?
- Has CISA KEV, Shadowserver, GreyNoise, or a trusted vendor confirmed exploitation?
- Are there credible PoC repositories or only secondary reporting mentioning PoC?
- Is there underground/forum/leak-site discussion, or only public reporting?
Generated: 2026-06-18T16:20:07+00:00