Impact
The vulnerability identified as CVE-2026-20157 involves missing encryption in Cisco RoomOS software, classified under CWE-311. In its current state, sensitive data handled or transmitted by the system may be left in clear text, thereby allowing unauthorized parties to read or exfiltrate confidential information. This flaw does not directly grant code execution or denial of service, but the loss of confidentiality can lead to significant privacy violations, regulatory non‑compliance, and potential exploitation in multi‑tenant environments where data segregation is critical.
Affected Systems
This issue affects Cisco RoomOS Software running on Cisco devices. Specific product versions are not enumerated in the advisory, but the affected distribution is the overall Cisco RoomOS firmware/releases currently deployed in affected environments.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for confidentiality, with the EPSS score of greater than 0% but less than 1% suggesting a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Based on the description, the likely attack vector involves capturing unencrypted data in transit or at rest; thus, attackers who can tap network traffic or compromise local storage may benefit. No additional prerequisites are specified, so the flaw could be remotely exploitable in data streams that lack TLS or other safeguards.
OpenCVE Enrichment