PT-2025-42379 · Cisco · Cisco Desk Phone 9800 Series+3
Published
2025-10-15
·
Updated
2025-12-04
·
CVE-2025-20350
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Desk Phone 9800 Series
Cisco IP Phone 7800 Series
Cisco IP Phone 8800 Series
Cisco Video Phone 8875
Description
A flaw exists in the web UI of the listed Cisco phone series running Cisco SIP Software that could allow a remote, unauthenticated attacker to cause a Denial of Service (DoS) condition. This is due to a buffer overflow when the device processes HTTP packets. An attacker could exploit this by sending crafted HTTP input to the device, potentially causing it to reload and become unavailable. To exploit this, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled.
Recommendations
Disable Web Access on Cisco Desk Phone 9800 Series devices.
Disable Web Access on Cisco IP Phone 7800 Series devices.
Disable Web Access on Cisco IP Phone 8800 Series devices.
Disable Web Access on Cisco Video Phone 8875 devices.
Fix
DoS
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Desk Phone 9800 Series
Cisco Ip Phone 7800 Series
Cisco Ip Phone 8800 Series
Cisco Video Phone 8875