{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 194 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24810-security-advisory-0194"
      }
    ],
    "title": "Security Advisory 194",
    "tracking": {
      "current_release_date": "2026-10-06T07:37:39Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 194",
      "initial_release_date": "2026-10-06T07:37:39Z",
      "revision_history": [
        {
          "date": "2026-10-06T07:37:39Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "WiFi version 22.1.1F-61",
                    "product": {
                      "name": "WiFi version 22.1.1F-61",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 1.0.0",
                    "product": {
                      "name": "WiFi version 1.0.0",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 21.4.0M-12",
                    "product": {
                      "name": "WiFi version 21.4.0M-12",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "WiFi"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-102168",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1774072"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is not possible.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "Captive Portal must be enabled on at least one SSID, along with an associated client and LAN network. If Captive Portal is not configured, the portal service is not running and the access point is not exposed to these vulnerabilities.",
          "title": "1774072: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-1"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-2"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102168"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v21.4.0M-12",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v22.1.1F-61",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in WiFi version mwm-v1.0.0",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "mitigation",
          "details": "If Captive Portal is not required, disabling Captive Portal on all SSIDs eliminates exposure. If a Captive Portal is required, there is no mitigation available."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-2",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-102168"
    },
    {
      "cve": "CVE-2026-102169",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1846913"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the captive portal. Remote code execution is not possible.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "Captive Portal must be enabled on at least one SSID, along with an associated client and LAN network. If Captive Portal is not configured, the portal service is not running and the access point is not exposed to these vulnerabilities.",
          "title": "1846913: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-1"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-2"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102169"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v21.4.0M-12",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v22.1.1F-61",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in WiFi version mwm-v1.0.0",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "mitigation",
          "details": "If Captive Portal is not required, disabling Captive Portal on all SSIDs eliminates exposure. If a Captive Portal is required, there is no mitigation available."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-2",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-102169"
    }
  ]
}