Impact
The disclosed issues involve erroneous arithmetic or logical calculations, catalogued as CWE-682, which can produce unexpected results within Cisco networking products. In practice, such miscalculations may alter configuration parameters, routing tables, or firmware operation, potentially causing devices to behave incorrectly or become unavailable. The adverse effects are limited to the affected device or device cluster and could lead to degraded network performance or temporary denial of service if the faulty calculations persist.
Affected Systems
Affected products include Cisco Campus Gateway Software along with the Meraki family devices: MR wireless access points, MV firmware, and MX firmware. No specific firmware or software version numbers are specified in the advisory; therefore, all releases that contain the hardening code are presumed vulnerable until the update is applied, and earlier releases lacking the hardening code remain at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying that no active exploitation has been documented. Based on the nature of the vulnerability, the likely attack vector involves management or configuration traffic sent to the device that can trigger the erroneous calculation logic. The risk is moderate to high for environments where device configuration is accessible without strict controls.
OpenCVE Enrichment