{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 193 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24809-security-advisory-0193"
      }
    ],
    "title": "Security Advisory 193",
    "tracking": {
      "current_release_date": "2026-10-06T07:37:35Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 193",
      "initial_release_date": "2026-10-06T07:37:35Z",
      "revision_history": [
        {
          "date": "2026-10-06T07:37:35Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "WiFi version 21.4.0M-12",
                    "product": {
                      "name": "WiFi version 21.4.0M-12",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 1.0.0",
                    "product": {
                      "name": "WiFi version 1.0.0",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 22.1.1F-61",
                    "product": {
                      "name": "WiFi version 22.1.1F-61",
                      "product_id": "CSAFPID-1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "WiFi"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-102162",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1774040"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition or potentially execute arbitrary code on the device. The wireless gateway service is automatically restarted after a crash, allowing repeated exploitation attempts.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "Captive portal, or application firewall must be enabled on at least one SSID. If none of these features are configured, the web gateway service does not perform the lookups that expose this vulnerability. Additionally, this can be exploited by an associated client.",
          "title": "1774040: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-2"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102162"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v21.4.0M-12",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v22.1.1F-61",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in WiFi version mwm-v1.0.0",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "mitigation",
          "details": "If captive portal and application firewall are not required, disabling these features on all SSIDs eliminates exposure to this vulnerability. Note: disabling captive portal removes guest authentication enforcement. Disabling application visibility removes per-application traffic analytics."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-1",
            "CSAFPID-2",
            "CSAFPID-0"
          ]
        }
      ],
      "title": "CVE-2026-102162"
    }
  ]
}