CVE-2026-102164

Summary

On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksWi-Fi Access Points22.0.0 <= 22.0.1F-32affected
Arista NetworksWi-Fi Access Points21.3.0 <= 21.3.0M-13affected
Arista NetworksWi-Fi Access Points1.0.0 < 21.3.0affected

Weaknesses

  • CWE-125: CWE-125 Out-of-bounds Read

Workarounds

If VXLAN tunnelling with L2-proxy is not required, disabling this configuration eliminates exposure.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References