Executive brief
Cisco's desk, IP, and video phones running SIP software contain a memory management flaw that can be exploited remotely to cause service outages. An attacker sending crafted HTTP packets can force the phones to consume memory until they become unresponsive, requiring manual reboot. This affects phones that are registered to Cisco Unified Communications Manager and have Web Access enabled (disabled by default), potentially impacting enterprise communication infrastructure.
Technical details
The vulnerability is a memory management flaw (CWE-401) triggered by improper handling of HTTP packets in Cisco SIP Software running on affected phone models. The attack vector is network-based and requires no authentication, but is only exploitable if the target phone is registered to Unified CM and has the Web Access feature enabled (off by default). An attacker sends a continuous stream of specially crafted HTTP requests that cause the device to repeatedly allocate memory without proper cleanup, leading to memory exhaustion and denial of service. Recovery requires manual device reboot. Cisco has released software updates; disabling Web Access mitigates the risk until patching is possible.
Affected products
- Cisco Desk Phone 9800 Series SIP Software versions prior to 4.1(1)SR1
- Cisco IP Phone 7800 Series SIP Software (vulnerable versions as indicated in advisory)
- Cisco IP Phone 8800 Series SIP Software (vulnerable versions as indicated in advisory)
- Cisco Video Phone 8875 SIP Software versions prior to 4.1(1)SR1
Timeline
- 2026-09-02: disclosed: Cisco Security Advisory published