Denial of Service Vulnerability in Cisco Desk and IP Phones
CVE-2026-20281

7.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
2 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20281?

This vulnerability affects several Cisco phone models, allowing an unauthenticated remote attacker to trigger a denial of service condition. It arises from improper memory management when the device processes HTTP packets. By sending a continuous stream of specially crafted HTTP packets, an attacker can exploit this vulnerability, causing the affected device to consume memory excessively. To recover from this state, a manual reboot of the device is necessary. For successful exploitation, the phone must be registered with Cisco Unified Communications Manager and have Web Access enabled, a feature that is disabled by default.

Affected Version(s)

Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1

Cisco Session Initiation Protocol (SIP) Software 11.5(1)

Cisco Session Initiation Protocol (SIP) Software 10.3(2)

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.