Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-102164 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train
Vendor Workaround
If VXLAN tunnelling with L2-proxy is not required, disabling this configuration eliminates exposure.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible. | |
| Title | Security Advisory 0196 | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:07:54.692Z
Reserved: 2026-09-28T17:45:17.722Z
Link: CVE-2026-102164
Updated: 2026-10-06T20:07:51.355Z
Status : Received
Published: 2026-10-06T20:17:11.667
Modified: 2026-10-06T21:17:03.367
Link: CVE-2026-102164
No data.
OpenCVE Enrichment
No data.