logo

Cisco Patches High-Severity CVE-2025-20350 DoS Flaw in Desk and IP Phones

ID: 2f43b684-e0a1-576b-98cf-83da7a318f5e

STIX ID: report--2f43b684-e0a1-576b-98cf-83da7a318f5e

Feed Name: securityonline.info

Threat Score
45/100

Date Published: 2025-10-17

Date Updated: 2026-04-22

Author: Ddos

...
...

Cisco has released patches for two vulnerabilities (CVE-2025-20350 – buffer overflow enabling remote DoS, CVE-2025-20351 – insufficient input validation enabling XSS) affecting multiple Cisco Desk and IP Phone models (9800, 7800, 8800, 8875 series). Both issues require Web Access to be enabled and the device registered to Cisco Unified Communications Manager to be exploitable; Web Access is disabled by default, limiting exposure, and Cisco recommends applying the provided fixed SIP Software releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.