Home Cisco CVE-2025-20350
Back to Cisco

CVE-2025-20350

Cisco SIP Software - Web UI

Cisco CVSS 7.5 Updated March 16, 2026

Executive Risk Summary

"A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. The vulnerability is due to a buffer overflow when an affected device processes HTTP packets, and can be exploited by sending crafted HTTP input to the device."

Operational Audit Arsenal

Target Type Firmware Image
Target Asset Cisco SIP Software
Standard Path Global Firmware

Manual Verification Required

This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

High

Internal Work Notes

CVE-2025-20350: Unauthenticated DoS vulnerability in Cisco SIP Software - Web UI, requiring firmware update to prevent remote attacks causing device reload

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Cisco Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.