Memory Disclosure Vulnerability in Arista Access Points with VXLAN Tunnelling
CVE-2026-102164

2.3LOW

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-102164?

A specific vulnerability in Arista access points configured with VXLAN tunnelling and L2-proxy allows wireless clients associated with the tunnelled SSID to send crafted packets. This may lead the access point to expose sensitive memory contents within network traffic, potentially allowing unauthorized access to sensitive information. However, the vulnerability does not allow for remote code execution or write primitives, limiting the extent of its potential impact.

Affected Version(s)

Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32

Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13

Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.