Executive brief
Cisco RoomOS, the operating system for Cisco collaboration and video conferencing devices, is affected by a vulnerability that could allow a remote attacker to cause a service disruption. By sending specific traffic that the system fails to handle correctly, an attacker could cause the device to crash or become unresponsive. This impact is limited to the availability of the device and does not involve the theft of sensitive data or unauthorized access to the system.
Technical details
A vulnerability in Cisco RoomOS software stems from improper handling of exceptional conditions, categorized under CWE-703 (which includes issues like uncaught exceptions or reachable assertions). A remote, unauthenticated attacker could exploit this by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to cause a denial-of-service (DoS) condition, leading to a device crash or reload. This vulnerability was discovered during internal security reviews and software hardening efforts. Cisco has released updates to address this issue; no workarounds are available.
Affected products
- Cisco RoomOS Software 11 and earlier; 26 before 26.5.2.2
Timeline
- 2026-07-15: disclosed
- 2026-07-15: advisory
- 2026-07-15: patched