Cisco RoomOS Buffer Overflow (cisco-sa-roomos-bof-vTMANZgu)

medium Nessus Plugin ID 341182

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco RoomOS Software is affected by a vulnerability.

- A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges.
This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges. (CVE-2026-20302)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCwu31332

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu31332

http://www.nessus.org/u?435297ec

Plugin Details

Severity: Medium

ID: 341182

File Name: cisco-sa-roomos-bof-vTMANZgu.nasl

Version: 1.2

Type: Remote

Family: CISCO

Published: 8/28/2026

Updated: 8/28/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.51

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-20302

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/a:cisco:telepresence_collaboration_endpoint

Required KB Items: Cisco/TelePresence_MCU/Device, Cisco/TelePresence_MCU/Version

Patch Publication Date: 8/19/2026

Vulnerability Publication Date: 8/19/2026

Reference Information

CVE: CVE-2026-20302

CISCO-SA: cisco-sa-roomos-bof-vTMANZgu

IAVA: 2026-A-0895

CISCO-BUG-ID: CSCwu31332