Impact
Improper control of a resource throughout its lifetime can allow an attacker to interfere with resource allocation, use, or deallocation, which may cause exhaustion of system resources or grant unauthorized access. The weakness is classified under CWE‑664.
Affected Systems
Cisco RoomOS software is affected. No specific product versions are listed by the CNA; therefore, all installations of Cisco RoomOS that have not yet received the hardening release remain at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity; the EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild at this time. This vulnerability is not listed in CISA KEV, implying no known widespread exploitation. Based on the description, it is inferred that the attack vector could involve local or privileged access, though the exact path of exploitation is not disclosed.
OpenCVE Enrichment