Cisco Desk, IP, and Video Phones Vulnerable to Remote DoS and XSS Attacks
Cisco has identified vulnerabilities affecting multiple desk, IP, and video phones due to flaws in their Session Initiation Protocol (SIP) software. These vulnerabilities expose the devices to remote denial-of-service (DoS) and cross-site scripting (XSS)…
Cisco has identified vulnerabilities affecting multiple desk, IP, and video phones due to flaws in their Session Initiation Protocol (SIP) software. These vulnerabilities expose the devices to remote denial-of-service (DoS) and cross-site scripting (XSS) attacks.
The vulnerabilities impact the following models when registered with Cisco Unified Communications Manager with Web Access enabled:
Desk Phone 9800 Series IP Phone 7800 and 8800 Series Video Phone 8875
No workarounds are available, making it imperative to update to the fixed software releases.
According to Cisco's advisory cisco-sa-phone-dos-FPyjLV7A dated Wed, Oct 15, 2025, two main vulnerabilities are disclosed:
A buffer overflow triggered by specially crafted HTTP packets, causing a DoS condition. An XSS vulnerability allowing attackers to inject malicious scripts through unsanitized inputs.
Web Access must be active for these vulnerabilities to be exploited, though it is disabled by default.
Cisco has identified vulnerabilities affecting multiple desk, IP, and video phones due to flaws in their Session Initiation Protocol (SIP) software.
Customers are advised to upgrade the affected devices to the fixed SIP software versions as detailed in Cisco’s advisory. Disabling Web Access can mitigate the risks but may affect device management. Administrators can manage this setting via the Communications Manager or the Bulk Administration Tool for large-scale operations.
CVE ID Vulnerability Type CVSS Base Score Security Impact
CVE-2025-20350 Remote DoS (Buffer Overflow) 7.5 High
CVE-2025-20351 Cross-Site Scripting (XSS) 6.1 Medium
Devices using Multiplatform Firmware are not affected by these vulnerabilities.
The following software releases resolve the vulnerabilities:
Desk Phone 9800 Series: SIP Software 3.3(1) or later IP Phone 7800 and 8800 Series: 14.3(1)SR2 or later Video Phone 8875: SIP Software 3.3(1) or later
Organizations relying on these phones for communication may face significant disruptions. A DoS attack could take multiple devices offline, impacting voice services. An XSS attack could potentially expose session data or allow unauthorized script execution, compromising administrative sessions.
Delaying updates increases exposure to these risks. Administrators should verify Web Access status on all registered phones and schedule updates during maintenance windows to minimize disruption. The Bulk Administration Tool provides an efficient way to manage updates for numerous devices.
Staying informed of Cisco's security advisories and promptly applying patches is crucial for maintaining secure operations.
Based on reporting by GBHackers.
