Buffer Overflow Vulnerability in Cisco Desk Phones and Video Phones
CVE-2025-20350
What is CVE-2025-20350?
A vulnerability exists within the web UI of Cisco Desk Phones and Video Phones, specifically affecting devices running Cisco SIP Software. This issue arises from a buffer overflow when the device processes certain HTTP packets. An attacker can exploit this flaw by sending specially crafted HTTP input to the device, which may lead to a denial-of-service condition. It is crucial to note that for this vulnerability to be exploited, the device must be registered to Cisco Unified Communications Manager with Web Access enabled, which is disabled by default.
Affected Version(s)
Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1
Cisco Session Initiation Protocol (SIP) Software 11.5(1)
Cisco Session Initiation Protocol (SIP) Software 10.3(2)
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved