CVE-2026-102163

Summary

On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksWi-Fi Access Points22.0.0 <= 22.0.1F-32affected
Arista NetworksWi-Fi Access Points21.3.0 <= 21.3.0M-13affected
Arista NetworksWi-Fi Access Points1.0.0 < 21.3.0affected

Weaknesses

  • CWE-787: CWE-787 Out-of-bounds Write

Workarounds

There is no mitigation or workaround available.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References