Impact
The vulnerability is due to improper input validation in Cisco RoomOS Software, classified as CWE‑20. An attacker who can supply malformed data may trigger unexpected system behavior, potentially resulting in a denial‑of‑service or integrity compromise if the data is used in privileged operations. No remote code execution path is mentioned in the advisory.
Affected Systems
All Cisco RoomOS Software deployments released before the hardening release are considered affected. The advisory does not list specific versions, so any installation on the vulnerable platform prior to the patch should be treated as at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% suggests a very low probability of exploitation currently. The vulnerability is not included in CISA's KEV catalog. The likely attack vector is the transmission of specially crafted input to a network‑exposed interface, such as a management API or configuration endpoint. No publicly available exploitation code or proof of concept is documented, so the risk of an active threat appears limited at this time.
OpenCVE Enrichment