{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 198 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24814-security-advisory-0198"
      }
    ],
    "title": "Security Advisory 198",
    "tracking": {
      "current_release_date": "2026-10-06T07:37:48Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 198",
      "initial_release_date": "2026-10-06T07:37:48Z",
      "revision_history": [
        {
          "date": "2026-10-06T07:37:48Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "WiFi version 22.1.1F-61",
                    "product": {
                      "name": "WiFi version 22.1.1F-61",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 1.0.0",
                    "product": {
                      "name": "WiFi version 1.0.0",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "WiFi version 21.4.0M-12",
                    "product": {
                      "name": "WiFi version 21.4.0M-12",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "WiFi"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-102165",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1846910"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "A Live Packet Capture session using \"Wireshark on local machine\" as the streaming option, which is a non-default operation, must be actively running from the management UI to expose this vulnerability. The capture service only listens while a capture session is active. Once initiated, the access point remains vulnerable to any attacker with network access to the capture service for the duration of the capture session. If no Live Packet Capture session with \"Wireshark on local machine\" as the streaming option is in progress, the access point is not exposed to this vulnerability.",
          "title": "1846910: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-1"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-2"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-102165"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v21.4.0M-12",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in WiFi version wifi-v22.1.1F-61",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in WiFi version mwm-v1.0.0",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "mitigation",
          "details": "When using Live Packet Capture, use \"Upload to server\" as the streaming option."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-2",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-102165"
    }
  ]
}