Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
CVE-2026-102165 has been fixed in the following releases: - 22.1.1F-61 and later release in the 22.x train - 21.4.0M-12 and later releases in the 21.x train
Vendor Workaround
When using Live Packet Capture, use "Upload to server" as the streaming option instead of "Wireshark on local machine".
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode. | |
| Title | Security Advisory 0198 | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-10-06T20:00:05.234Z
Reserved: 2026-09-28T17:45:17.722Z
Link: CVE-2026-102165
Updated: 2026-10-06T19:59:59.885Z
Status : Received
Published: 2026-10-06T20:17:11.800
Modified: 2026-10-06T21:17:03.490
Link: CVE-2026-102165
No data.
OpenCVE Enrichment
No data.
-
CWE-121
Stack-based Buffer Overflow