Impact
The vulnerability is a flaw in Cisco RoomOS software where improper access control is present. It is classified under CWE‑284, indicating that access permissions are not correctly validated, which could enable unauthorized actions.
Affected Systems
The affected product is Cisco RoomOS Software from Cisco. No specific version information is provided in the advisory, so all installations of the baseline RoomOS firmware remain potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity; however, the EPSS score of less than 1% suggests a low current probability of exploitation. The vulnerability is not yet listed in CISA's KEV catalog. The advisory does not explicitly state the attack vector; it is inferred that an attacker could exploit the improper access control remotely, possibly via exposed interfaces, but the exact method is not detailed.
OpenCVE Enrichment