Denial of Service Vulnerability in Cisco Desk and IP Phones
CVE-2026-20281
What is CVE-2026-20281?
This vulnerability affects several Cisco phone models, allowing an unauthenticated remote attacker to trigger a denial of service condition. It arises from improper memory management when the device processes HTTP packets. By sending a continuous stream of specially crafted HTTP packets, an attacker can exploit this vulnerability, causing the affected device to consume memory excessively. To recover from this state, a manual reboot of the device is necessary. For successful exploitation, the phone must be registered with Cisco Unified Communications Manager and have Web Access enabled, a feature that is disabled by default.
Affected Version(s)
Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1
Cisco Session Initiation Protocol (SIP) Software 11.5(1)
Cisco Session Initiation Protocol (SIP) Software 10.3(2)