PT-2026-84813 · Cisco · Desk Phone 9800 Series+5

CVE-2026-20281

·

Published

2026-09-02

·

Updated

2026-09-05

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Desk Phone 9800 Series (affected versions not specified) Cisco IP Phone 7800 Series (affected versions not specified) Cisco IP Phone 8800 Series (affected versions not specified) Cisco Video Phone 8875 (affected versions not specified)
Description Improper memory management when processing HTTP packets in Cisco Session Initiation Protocol (SIP) Software allows an unauthenticated remote attacker to cause a denial of service (DoS) condition. An attacker can exploit this by sending a continuous stream of crafted HTTP packets, causing the device to exhaust its memory. Recovery requires a manual reboot. This issue is only exploitable if the device is registered to Cisco Unified Communications Manager (Unified CM) and has Web Access enabled, which is disabled by default.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Disable Web Access on the affected devices to prevent exploitation.

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20281

Affected Products

Desk Phone 9800 Series
Ip Phone 7800 Series
Ip Phone 8800 Series
Cisco Session Initiation Protocol (Sip)
Cisco Unified Communications Manager
Video Phone 8875