Cisco Patches High-Severity CVE-2025-20350 DoS Flaw in Desk and IP Phones
ID: 2f43b684-e0a1-576b-98cf-83da7a318f5e
STIX ID: report--2f43b684-e0a1-576b-98cf-83da7a318f5e
Feed Name: securityonline.info
Cisco has released patches for two vulnerabilities (CVE-2025-20350 – buffer overflow enabling remote DoS, CVE-2025-20351 – insufficient input validation enabling XSS) affecting multiple Cisco Desk and IP Phone models (9800, 7800, 8800, 8875 series). Both issues require Web Access to be enabled and the device registered to Cisco Unified Communications Manager to be exploitable; Web Access is disabled by default, limiting exposure, and Cisco recommends applying the provided fixed SIP Software releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
