Security Advisory Desk
highQCS priority 100/100Cisco

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Certain Cisco desk and video phones have a security flaw that can allow remote attackers to disable the phone by overloading its memory using specially crafted web packets. This causes the phone to stop working until it is manually restarted. To be vulnerable, the phone must be registered with Cisco Unified Communications Manager and have its Web Access feature turned on, which it is not by default. Cisco has released updates that fix this issue, but no temporary workaround fully addresses the problem.

Published 2/9/2026, 4:00:00 pmVerified 3/9/2026, 12:08:11 amRevision 1
Cisco high network security advisory visual

In plain language

What this advisory means

Certain Cisco desk and video phones have a security flaw that can allow remote attackers to disable the phone by overloading its memory using specially crafted web packets. This causes the phone to stop working until it is manually restarted. To be vulnerable, the phone must be registered with Cisco Unified Communications Manager and have its Web Access feature turned on, which it is not by default. Cisco has released updates that fix this issue, but no temporary workaround fully addresses the problem.

Technical explanation

How the issue affects the environment

The vulnerability affects Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 running Cisco SIP Software. It stems from improper memory management during processing of HTTP packets. An unauthenticated remote attacker can exploit this by sending a continuous stream of crafted HTTP packets, causing the device to consume memory continuously, leading to a Denial of Service (DoS) condition. Recovery requires a manual reboot. Exploitation requires the phone to be registered with Cisco Unified Communications Manager and have Web Access enabled, which is disabled by default. Cisco has released software versions fixing this memory management flaw, eliminating the DoS risk.

Operational impact

Why teams should care

A successful exploit can cause affected Cisco phones to become unresponsive, disrupting voice and video communications critical to business operations. This denial of service requires manual device reboot, leading to potential downtime and operational disruption. The vulnerability poses a high security impact, especially in environments relying heavily on Cisco Unified Communications infrastructure, risking business productivity and communication reliability.

Immediate action

Cisco strongly recommends upgrading affected devices to the specified fixed software releases to remediate this vulnerability. This eliminates the improper memory management issue and prevents the denial of service condition.

Affected and fixed releases

Affected versionsCisco SIP Software Releases 4.1(1)SR1 and earlier for Desk Phone 9800 Series and Video Phone 8875, Cisco SIP Software Releases earlier than 14.4 for IP Phone 7800 and 8800 Series
Fixed versionsCisco SIP Software 5.0(1) for Desk Phone 9800 Series and Video Phone 8875, Cisco SIP Software 14.4(1)SR3 for IP Phone 7800 and 8800 Series

Temporary risk reduction

There are no full workarounds that address this vulnerability. However, disabling Web Access on the affected phones mitigates the vulnerability since Web Access must be enabled for exploitation. Web Access is disabled by default. Disabling it can be done through Cisco Unified Communications Manager.

Evidence and validation checklist

  • Cisco official security advisory confirming vulnerability details
  • Description of the memory management flaw triggered by crafted HTTP packets
  • Requirements for exploitation (Unified CM registration, Web Access enabled)
  • Disclosure of no known public exploits or active attacks
  • Release notes listing fixed software versions

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source