Buffer Overflow Vulnerability in Cisco Desk Phones and Video Phones
CVE-2025-20350

7.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 October 2025

Badges

👾 Exploit Exists

What is CVE-2025-20350?

A vulnerability exists within the web UI of Cisco Desk Phones and Video Phones, specifically affecting devices running Cisco SIP Software. This issue arises from a buffer overflow when the device processes certain HTTP packets. An attacker can exploit this flaw by sending specially crafted HTTP input to the device, which may lead to a denial-of-service condition. It is crucial to note that for this vulnerability to be exploited, the device must be registered to Cisco Unified Communications Manager with Web Access enabled, which is disabled by default.

Affected Version(s)

Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1

Cisco Session Initiation Protocol (SIP) Software 11.5(1)

Cisco Session Initiation Protocol (SIP) Software 10.3(2)

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20350 : Buffer Overflow Vulnerability in Cisco Desk Phones and Video Phones