Impact
The vulnerability is a stack buffer overflow in the USB driver of Cisco RoomOS that can be triggered when a malicious USB device is connected. An attacker with physical access to the USB port can exploit the lack of boundary checks on driver data to execute arbitrary code as root, compromising the device’s confidentiality, integrity, and availability.
Affected Systems
Cisco RoomOS Software on devices that expose a USB port.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. Because the attack requires local physical access to a USB port, exploitation is limited to on‑premises or authorized personnel with physical proximity, but once accessed the attacker can gain full root privileges. Organizations should therefore consider this a significant local privilege escalation risk.
OpenCVE Enrichment