{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 191 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24807-security-advisory-0191"
      }
    ],
    "title": "Security Advisory 191",
    "tracking": {
      "current_release_date": "2026-10-06T07:37:28Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 191",
      "initial_release_date": "2026-10-06T07:37:28Z",
      "revision_history": [
        {
          "date": "2026-10-06T07:37:28Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "WiFi version 1.0.0",
                    "product": {
                      "name": "WiFi version 1.0.0",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 2026.2.1",
                    "product": {
                      "name": "WiFi version 2026.2.1",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "WiFi"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-102156",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1731907"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper neutralization of Lightweight Directory Access Protocol (LDAP) authentication input may allow an unauthenticated network attacker, under high-complexity conditions, to inject queries against the configured directory service.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "both of the following conditions must be met:\n\n1. CV-CUE backend (wifimanager) must be enabled and running.\n2. LDAP authentication must be enabled for the User Accounts.\n\nHere is an example of the command to inspect the status of wifimanager:\n```\n[root@]# cvpi status wifimanager \nExecuting command. This may take some time... \nCompleted 1/1 discovered actions \nprimary components total:1 running:1 disabled:0  \n```\n\nHere is an example screenshot of the \"LDAP Authentication\" configuration option enabled: <image For LDAP Authentication>",
          "title": "1731907: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-1"
        ],
        "fixed": [
          "CSAFPID-0"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102156"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version 2026.2.1",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in WiFi version 1.0.0",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "mitigation",
          "details": "The recommended mitigation is to disable LDAP Authentication. Prior to implementing this, please ensure that an alternative authentication mechanism is properly configured and verified, as disabling LDAP authentication will prevent LDAP-dependent users from accessing or managing CV-CUE, which may render the management service unavailable to them.\n\nHere is an example screenshot of the \"LDAP Authentication\" configuration option: <image For LDAP Authentication unconfigured>"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-102156"
    }
  ]
}