Impact
The vulnerability stems from inadequate enforcement of memory buffer boundaries, classified as CWE‑119. An attacker who can supply malformed input to RoomOS may cause a buffer overflow, potentially corrupting memory and leading to arbitrary code execution or a crash that results in denial of service.
Affected Systems
The affected product is Cisco RoomOS Software from Cisco. No specific version ranges are listed, meaning all known releases could be impacted until patched.
Risk and Exploitability
The CVSS score of 8.1 signifies a high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not currently catalogued in the CISA KEV list. Based on the description, the likely attack vector would involve an attacker sending specially crafted data to a vulnerable RoomOS interface; the exact prerequisites are not disclosed, so both local and network‑based exploitation remain plausible.
OpenCVE Enrichment