Impact
A flaw in the logging subsystem of Cisco RoomOS allows an authenticated local attacker with low privileges to enable a high‑level logging mode and obtain system logs that contain sensitive data such as user login credentials. The weakness corresponds to CWE‑532, the logging of sensitive information. As a result, confidentiality is compromised, but integrity and availability are not directly affected.
Affected Systems
The vulnerability affects Cisco RoomOS Software. No specific version numbers were enumerated in the advisory, so all installations of this software are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity. Because the exploit requires local authentication and low privileges, the attack surface is limited to users who can log on to the device. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not been observed yet. Nevertheless, an attacker with local access could read logged credentials, potentially enabling credential theft or further lateral movement within the network.
OpenCVE Enrichment