On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

CVE-2026-102164 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train


Workaround

If VXLAN tunnelling with L2-proxy is not required, disabling this configuration eliminates exposure.

History

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible.
Title Security Advisory 0196
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-10-06T20:07:54.692Z

Reserved: 2026-09-28T17:45:17.722Z

Link: CVE-2026-102164

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:11.667

Modified: 2026-10-06T20:17:11.667

Link: CVE-2026-102164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses