Description
A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition.
Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.
Published: 2026-09-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Cisco Session Initiation Protocol (SIP) Software embedded in the Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 allows an unauthenticated, remote attacker to trigger a denial of service by sending a continuous stream of crafted HTTP packets. The flaw stems from improper memory management during HTTP packet processing, resulting in uncontrolled memory consumption. When exploited, the device continually consumes memory until it becomes unresponsive, requiring a manual reboot to recover. The phone must be registered to Cisco Unified Communications Manager and have Web Access enabled for the vulnerability to be exploitable; Web Access defaults to disabled.

Affected Systems

Affected devices are all Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco Session Initiation Protocol (SIP) Software. Versions are not specified, so all firmware releases for these models are potentially vulnerable until a patch is applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits yet. However, the attack vector is remote and unauthenticated, requiring the phone to have Web Access enabled and be registered to a Unified Communications Manager. The exploit would cause a persistent DoS that demands a physical or remote reboot to restore service.

Generated by OpenCVE AI on September 3, 2026 at 10:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cisco SIP Software firmware on all affected devices to the latest release that includes the fix.
  • Disable Web Access on any phones that do not require it, since Web Access is the entry point for the attack.
  • Implement firewall or segmentation rules to restrict HTTP traffic to the phones and monitor for abnormal traffic patterns that may indicate an attack.
  • Plan for swift reboot or failover procedures in the event of a DoS to minimize service disruption.

Generated by OpenCVE AI on September 3, 2026 at 10:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco session Initiation Protocol (sip) Firmware
Vendors & Products Cisco
Cisco session Initiation Protocol (sip) Firmware

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition.&nbsp;A manual reboot of the device is required to recover from this condition. Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.
Title Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
Weaknesses CWE-401
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Cisco Session Initiation Protocol (sip) Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-02T17:58:58.216Z

Reserved: 2025-10-08T11:59:15.403Z

Link: CVE-2026-20281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T17:17:33.730

Modified: 2026-09-02T19:23:13.660

Link: CVE-2026-20281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime