Memory Disclosure Vulnerability in Arista Access Points with VXLAN Tunnelling
CVE-2026-102164
2.3LOW
What is CVE-2026-102164?
A specific vulnerability in Arista access points configured with VXLAN tunnelling and L2-proxy allows wireless clients associated with the tunnelled SSID to send crafted packets. This may lead the access point to expose sensitive memory contents within network traffic, potentially allowing unauthorized access to sensitive information. However, the vulnerability does not allow for remote code execution or write primitives, limiting the extent of its potential impact.
Affected Version(s)
Wi-Fi Access Points Wi-Fi Access Points 22.0.0 <= 22.0.1F-32
Wi-Fi Access Points Wi-Fi Access Points 21.3.0 <= 21.3.0M-13
Wi-Fi Access Points Wi-Fi Access Points 1.0.0 < 21.3.0
