Buffer Overflow Vulnerability in Cisco Desk Phones and Video Phones
CVE-2025-20350
7.5HIGH
What is CVE-2025-20350?
A vulnerability exists within the web UI of Cisco Desk Phones and Video Phones, specifically affecting devices running Cisco SIP Software. This issue arises from a buffer overflow when the device processes certain HTTP packets. An attacker can exploit this flaw by sending specially crafted HTTP input to the device, which may lead to a denial-of-service condition. It is crucial to note that for this vulnerability to be exploited, the device must be registered to Cisco Unified Communications Manager with Web Access enabled, which is disabled by default.
Affected Version(s)
Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1
Cisco Session Initiation Protocol (SIP) Software 11.5(1)
Cisco Session Initiation Protocol (SIP) Software 10.3(2)