Impact
A vulnerability in the Cisco Session Initiation Protocol (SIP) Software embedded in the Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 allows an unauthenticated, remote attacker to trigger a denial of service by sending a continuous stream of crafted HTTP packets. The flaw stems from improper memory management during HTTP packet processing, resulting in uncontrolled memory consumption. When exploited, the device continually consumes memory until it becomes unresponsive, requiring a manual reboot to recover. The phone must be registered to Cisco Unified Communications Manager and have Web Access enabled for the vulnerability to be exploitable; Web Access defaults to disabled.
Affected Systems
Affected devices are all Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco Session Initiation Protocol (SIP) Software. Versions are not specified, so all firmware releases for these models are potentially vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits yet. However, the attack vector is remote and unauthenticated, requiring the phone to have Web Access enabled and be registered to a Unified Communications Manager. The exploit would cause a persistent DoS that demands a physical or remote reboot to restore service.
OpenCVE Enrichment