CVE-2026-20281
Received Received - Intake

DoS Condition in Cisco Desk Phone 9800 Series via HTTP Packet Handling

Vulnerability report for CVE-2026-20281, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Cisco Systems, Inc.

Description

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition. Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
cisco desk_phone_9800_series *
cisco ip_phone_7800_series *
cisco ip_phone_8800_series *
cisco video_phone_8875 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service (DoS) vulnerability in Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 running Cisco SIP Software. It occurs due to improper memory management when processing HTTP packets. An unauthenticated remote attacker can send crafted HTTP packets to cause the device to consume excessive memory, leading to a DoS condition that requires a manual reboot to recover.

Detection Guidance

Monitor network traffic for continuous streams of crafted HTTP packets targeting Cisco SIP phones. Check device logs for unusual memory consumption or unresponsiveness. Use network monitoring tools like Wireshark to inspect HTTP traffic patterns. Ensure Web Access is disabled on affected devices as it is required for exploitation.

Impact Analysis

An attacker could exploit this vulnerability to make your Cisco phone unresponsive, disrupting phone services and communications. This could affect business operations, customer support, or emergency communications. A manual reboot is required to restore normal function.

Mitigation Strategies

Disable Web Access on affected Cisco phones if not required for functionality. Upgrade to fixed software releases provided by Cisco. Ensure phones are not registered to Cisco Unified Communications Manager if not needed. Monitor devices for signs of DoS conditions and reboot affected devices if necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20281. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart