Cisco Desk/IP/Video Phone Denial of Service (cisco-sa-phone-dos-FPyjLV7A) (CVE-2025-20350)

high Nessus Plugin ID 271389

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, the remote Cisco Desk, IP, or Video Phone running SIP Software is affected by a denial of service vulnerability:

- A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to a buffer overflow when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending crafted HTTP input to the device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default. (CVE-2025-20350)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwn51601, CSCwn60480, CSCwn60481, CSCwn60482, CSCwn60484, CSCwn60491, CSCwn60492, CSCwn60493, or CSCwn60494

See Also

http://www.nessus.org/u?83c0dd77

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn51601

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60480

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60481

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60482

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60484

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60491

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60492

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60493

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwn60494

Plugin Details

Severity: High

ID: 271389

File Name: cisco-sa-phone-dos-FPyjLV7A_CVE-2025-20350.nasl

Version: 1.1

Type: combined

Family: CISCO

Published: 10/24/2025

Updated: 10/24/2025

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-20350

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: x-cpe:/h:cisco:ip_phone, x-cpe:/o:cisco:ip_phone

Required KB Items: installed_sw/Cisco IP Phone, Settings/ParanoidReport

Patch Publication Date: 10/15/2025

Vulnerability Publication Date: 10/15/2025

Reference Information

CVE: CVE-2025-20350