Executive brief
Cisco RoomOS, the operating system for Cisco collaboration and video conferencing devices, is affected by a security flaw where sensitive data is transmitted without encryption. An attacker with access to the local network could potentially intercept and read this information, leading to a loss of confidentiality. Cisco has released software updates to address this issue as part of a broader security hardening effort.
Technical details
This vulnerability belongs to the CWE-311 pillar (Missing Encryption of Sensitive Data) and was identified during Cisco's internal security testing of RoomOS. The flaw allows for the cleartext transmission of sensitive information, which could be intercepted by an unauthenticated attacker on the same adjacent network. The CVSS score of 7.5 reflects a high impact on confidentiality, integrity, and availability, though the attack complexity is rated as high. Cisco has consolidated multiple underlying issues of this class under a single CVE for this hardening release. Fixes are available in RoomOS versions 11.32.6.0, 11.39.1.1 (Cloud), 26.5.2.2, and June 2026 (Cloud) or later.
Affected products
- Cisco RoomOS Software RoomOS 11 and earlier; RoomOS 26 before 26.5.2.2
Timeline
- 2026-07-15: advisory: Initial public release by Cisco
- 2026-07-15: patched