Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
TL;DR 📌
Cisco has identified multiple vulnerabilities in the Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 that could allow unauthenticated remote attackers to cause denial of service (DoS) conditions or conduct cross-site scripting (XSS) attacks. The highest CVSS score is 7.5, indicating a high severity risk. Software updates are available to address these vulnerabilities, and there are no workarounds.
What happened 🕵️♂️
Cisco has reported vulnerabilities in its Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875, all running Cisco Session Initiation Protocol (SIP) Software. These vulnerabilities could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition or perform cross-site scripting (XSS) attacks against users of the web UI. Exploitation requires that the phone is registered to Cisco Unified Communications Manager and has Web Access enabled, which is disabled by default.
Affected products 🖥️
The following products are affected if they are running a vulnerable release of Cisco SIP Software, registered to Cisco Unified Communications Manager, and have Web Access enabled:
- Desk Phone 9800 Series
- IP Phone 7800 Series
- IP Phone 8800 Series
- Video Phone 8875
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 3 | 3.3(1) | |
| 14.3 | 14.3(1)SR2 | |
| 14.4 | Not vulnerable. | |
| 11 | 11.0(6)SR7 | |
| 2.3(1)SR1 and earlier | Migrate to a fixed release. | |
| 1.0 | Initial public release. | |
| Desk Phone 9800 Series | 3.3(1) | |
| IP Phone 7800 and 8800 Series | 14.3(1)SR2 | Earlier than 14.3 |
| IP Phone 8821 | 11.0(6)SR7 | Earlier than 11 |
| Video Phone 8875 | 3.3(1) | 2.3(1)SR1 and earlier |
Workarounds 🧯
There are no workarounds that address these vulnerabilities. However, disabling Web Access can mitigate the risks. To disable Web Access, administrative privileges are required on the Communications Manager.
Risk in context 🎯
With a CVSS score of 7.5, this vulnerability is rated as High. The exposure is significant if devices are internet-facing and have Web Access enabled. The potential for denial of service could disrupt communication services, impacting business operations. Immediate action is recommended to apply the necessary software updates.
Fast facts ⚡
- Vulnerabilities: Denial of service (CVE-2025-20350) and cross-site scripting (CVE-2025-20351).
- CVSS Score: 7.5 (High).
- Exploitation: Requires Web Access to be enabled.
- No workarounds available.
- Fixed software: Updates available for affected products.
For leadership 🧭
Executive summary. Two flaws in Cisco’s SIP phone software let an unauthenticated attacker crash desk and video phones or attack users through the device’s web interface, but only where Web Access has been turned on. Given no workarounds exist beyond disabling that feature, affected fleets should be scheduled for firmware upgrades in the next maintenance window.
Why it matters:
- Affects Desk Phone 9800 Series, IP Phone 7800/8800 Series and Video Phone 8875 when registered to Cisco Unified Communications Manager with Web Access enabled
- CVE-2025-20350 allows an unauthenticated remote attacker to force a denial of service, disrupting voice and video calls on the affected handsets
- CVE-2025-20351 enables cross-site scripting against users of the phone’s web UI, again without requiring authentication
- There is no workaround short of disabling Web Access, which itself needs administrative access to Communications Manager to change
Now / Next / Later:
- Now: Check which registered phones have Web Access enabled and disable it on any that don’t need it, using Communications Manager admin access.
- Next: Upgrade affected devices to the first fixed release for their train — 3.3(1) for Desk Phone 9800 and Video Phone 8875, 14.3(1)SR2 for IP Phone 7800/8800, or 11.0(6)SR7 for IP Phone 8821 — during the next change window.
- Later: Make Web Access disabled the default provisioning setting for SIP phones and only enable it on a case-by-case basis where genuinely required.