Sceawere

Vulnerability Detail

CVE-2026-20281UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cisco IP Phone Memory Exhaustion

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
13h ago
Vendor
Cisco
Product
Cisco Session Initiation Protocol (SIP) Software
Attack Type
Missing Release of Memory after Effective Lifetime
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition. Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-02T17:17:33.730Z",
  "pubdate": "2026-09-02T17:17:33.730Z",
  "executiveSummary": "This vulnerability is a memory management flaw identified within the HTTP packet processing logic of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software.\nThe vulnerability allows an unauthenticated, remote attacker to trigger a Denial of Service (DoS) condition. By flooding the targeted device with specifically crafted HTTP packets, an attacker can induce persistent memory exhaustion.\nSuccessful exploitation requires the device to be registered to Cisco Unified Communications Manager (Unified CM) and necessitates that Web Access be explicitly enabled, as it is disabled by default.\nThe impact is significant, as the device becomes unresponsive, effectively disrupting communication services. Recovery from this state is not automatic and necessitates a manual hardware reboot of the affected unit.",
  "technicalDetails": "The root cause of this vulnerability lies in improper memory management within the device's HTTP stack. When the affected Cisco SIP software processes incoming HTTP packets, it fails to correctly deallocate memory resources associated with specific packet headers or payloads, leading to a memory leak.\nAn unauthenticated, remote attacker can exploit this by transmitting a sustained, continuous stream of crafted HTTP packets to the target device's network interface. The device's internal HTTP server process attempts to allocate memory to handle these incoming requests; however, due to the identified logic flaw, the memory is not reclaimed after the processing task is complete.\nAs the attacker maintains the packet stream, the device's heap or buffer pool is incrementally exhausted. Once available system memory reaches a critical threshold, the device becomes incapable of processing new network traffic or maintaining standard SIP registration and telephony operations, resulting in a full Denial of Service (DoS) state.\nThe exploitation path requires the device to be currently registered to Cisco Unified Communications Manager (Unified CM). Furthermore, the attack surface is constrained by the requirement that the Web Access feature must be enabled on the phone. Because Web Access is configured to 'Disabled' by default in the standard deployment, the vulnerability is not exploitable in default configurations.\nThere are no requirements for valid authentication or elevated privileges, as the vulnerability is triggered at the network transport layer before authentication logic is fully realized for the web-based management interface. The payload behavior does not involve remote code execution (RCE) or arbitrary command injection, but rather focuses on the persistent accumulation of unallocated memory chunks.\nUpon reaching the DoS state, the device remains in a non-functional loop. The software is unable to self-recover or flush the leaked memory caches, and because the impact affects core system processes, the device cannot process management commands to resolve the state remotely. Consequently, the only path to restoration is a manual hard reboot of the physical hardware, which clears the volatile memory and resets the HTTP service state."
}
CVE-2026-20281: Cisco IP Phone Memory Exhaustion (HIGH Severity, CVSS: 7.5) - Sceawere