Cisco RoomOS Software是美国Cisco公司的一款视频会议软件。 Cisco RoomOS Software存在缓冲区错误漏洞,该漏洞源于USB驱动程序中特定数据的边界检查不足,可能导致未经身份验证的本地攻击者通过物理访问USB端口连接恶意USB设备,造成缓冲区溢出并以root权限执行任意代码。以下版本受到影响:RoomOS 10.11.2.2版本、RoomOS 10.15.2.2版本、RoomOS 11.5.4.6版本、RoomOS 11.5.2.4版本、RoomOS 10.8.2.5
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco RoomOS Software | RoomOS 10.11.2.2 |
affected |
RoomOS 10.15.2.2 |
affected | ||
RoomOS 11.5.4.6 |
affected | ||
RoomOS 11.5.2.4 |
affected | ||
RoomOS 10.8.2.5 |
affected | ||
RoomOS 10.11.5.2 |
affected | ||
RoomOS 10.11.3.0 |
affected | ||
RoomOS 10.15.5.3 |
affected | ||
| … +64 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco RoomOS Software | RoomOS 10.11.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20030 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20358 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20357 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20317 | 10.0 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentic |
| CVE-2026-20315 | 10.0 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Co |
| CVE-2026-20231 | 9.9 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutraliz |
| CVE-2026-20359 | 9.9 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20318 | 9.6 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Val |
| CVE-2026-20319 | 7.5 HIGH | Cisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management |
| CVE-2026-20320 | 7.5 HIGH | Cisco BroadWorks 输入验证错误漏洞 |
| CVE-2026-20327 | 6.5 MEDIUM | Cisco Unified Intelligence Center SQL Injection Vulnerability |
| CVE-2026-20232 | 5.4 MEDIUM | Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability |
| CVE-2026-20177 | 5.3 MEDIUM | Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability |
| CVE-2026-20314 | 5.0 MEDIUM | Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server- |
No comments yet