Project Subscriptions
No data.
No advisories yet.
Solution
CVE-2026-102164 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train
Workaround
If VXLAN tunnelling with L2-proxy is not required, disabling this configuration eliminates exposure.
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible. | |
| Title | Security Advisory 0196 | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:07:54.692Z
Reserved: 2026-09-28T17:45:17.722Z
Link: CVE-2026-102164
No data.
Status : Received
Published: 2026-10-06T20:17:11.667
Modified: 2026-10-06T20:17:11.667
Link: CVE-2026-102164
No data.
OpenCVE Enrichment
No data.