Impact
The vulnerability is a classic buffer management flaw represented by CWE-119. An attacker who can trigger the out‑of‑bounds memory operation could potentially overwrite critical data, leading to arbitrary code execution or denial of service on the affected device. The impact spans the confidentiality, integrity, and availability of the device’s software and could allow an attacker to control the network element or compromise adjacent devices if the flaw is exploited in a network‑wide context.
Affected Systems
Cisco Campus Gateway Software, Cisco Meraki MR Wireless Access Points Software, Cisco Meraki MV Firmware, and Cisco Meraki MX Firmware are all impacted. Specific affected firmware or software revisions are not disclosed in the advisory, and users should consult Cisco’s release notes for version details.
Risk and Exploitability
The CVSS score of 9.6 classifies this issue as critical, indicating a high likelihood of successful exploitation if the conditions are met. EPSS data is not available, but the absence of an observed exploit or inclusion in the CISA KEV catalogue does not reduce the severity. Based on the description, the likely attack vector involves remote network traffic that reaches the vulnerable buffer management routines, though local exploitation cannot be ruled out due to the nature of memory corruption defects.
OpenCVE Enrichment