High [CVE-2026-20281] Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
This high-severity Cisco advisory covers CVE-2026-20281 affecting Session Initiation Protocol (SIP) Software.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device.
A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition.
Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
- Scope: This vulnerability affects the following Cisco products if they are running a vulnerable release of Cisco SIP Software, are registered to Cisco Unified CM, and have Web Access enabled:
- 4.1(1)SR1 and earlier — Migrate to a fixed release
- Release 5 (first fixed: 5.0(1))
- Earlier than 14.4 — Migrate to a fixed release
- Release 14.4 (first fixed: 14.4(1)SR3)
- Release 14.4 (first fixed: 14.4(1)SR4)
- Earlier than 11.0 — Migrate to a fixed release
- Release 11.0 (first fixed: 11.0(6)SR8)
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
- 5.0(1)
- 14.4(1)SR3
- 14.4(1)SR4
- 11.0(6)SR8
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Release 4.1(1)SR1 and earlier: migrate to a fixed release.
- Release 5: upgrade to 5.0(1).
- Earlier than 14.4: migrate to a fixed release.
- Release 14.4: upgrade to 14.4(1)SR3.
- Earlier than 14.4: migrate to a fixed release.
- Release 14.4: upgrade to 14.4(1)SR4.
- Earlier than 11.0: migrate to a fixed release.
- Release 11.0: upgrade to 11.0(6)SR8.
- There are no workarounds that address this vulnerability. However, disabling Web Access mitigates this vulnerability.
- To disable Web Access on a specific device, follow these steps:
- Log in to the Unified CM to which the phone is registered using administrative privileges, which allow modification of devices.
- Choose Device > Phone.
- Enter the search criteria in the search box and click Find.
- Choose the appropriate device from the Device Name list.
- Under Web Access, use the toggle button to choose Disabled.
- Click Save.
- To verify that Web Access has been disabled, enter the IP address of the phone into a browser window on a device that has internet access, and click Enter. If the IP address is unreachable, Web Access has been disabled.
- To disable Web Access on multiple devices, use the Bulk Admin Tool (BAT) as detailed in the Bulk Administration Guide for Cisco Unified Communications Manager.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.