CVE-2026-102163: Security Advisory 0195
On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless association or authentication is required.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 21.4.0M-12Patch Security Advisory 0195 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 22.1.1F-61Patch Security Advisory 0195
Event History
Frequently Asked Questions
Which deployments are exposed?
Affected Arista access points are exposed when WIPS is active. The attacker must be within RF proximity of the access point.
Does exploitation require wireless association or credentials?
No. An unauthenticated attacker can send the crafted frame without associating to the wireless network or authenticating.
What is the potential impact of a successful attack?
The sensor service can crash, disabling WIPS monitoring on the access point. Remote code execution is also a potential outcome.