CVE-2026-102164
LOW
NVD
CVSS Score
3.1
Severity
LOW
Published
Oct 06, 2026
Vendor
unknown
Description
On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code execution is possible.