Impact
The CVE describes an improper control of a resource through its lifetime, falling under the Common Weakness Enumeration Pillar CWE-664. This weakness can allow an attacker to trigger resource exhaustion or denial of service by prematurely freeing, over-allocating, or mismanaging critical system resources, potentially leading to service degradation or crash.
Affected Systems
Affected products include Cisco Campus Gateway Software, Cisco Meraki MR Wireless Access Points Software, Cisco Meraki MV Firmware, and Cisco Meraki MX Firmware. No specific version information is provided in the advisory, so all firmware and software releases of these products may be impacted until a hardened release is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity level. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, implying a lower probability of widespread exploitation based on current data. The likely attack vector is inferred to be local or remote access to the device or software, depending on the configuration of the Meraki environment; however, the description does not explicitly detail the path of exploitation.
OpenCVE Enrichment