Cisco has issued a security advisory highlighting multiple vulnerabilities in its IP Phone 7800 and 8800 Series, Desk Phone 9800 Series, and Video Phone 8875 models running Cisco Session Initiation Protocol (SIP) Software. Published on October 15, 2025, the advisory warns of potential denial-of-service (DoS) and cross-site scripting (XSS) attacks that could affect devices with Web Access enabled while registered to Cisco Unified Communications Manager (CUCM)—a feature disabled by default. The most critical flaw, tracked as CVE-2025-20350, is a high-severity buffer overflow vulnerability with a CVSS score of 7.5. It can be triggered when crafted HTTP packets are processed by vulnerable devices, leading to device reboots and service disruption. This vulnerability is exploitable remotely, requires no user privileges, and is linked to bug ID CSCwn51601. It presents a serious risk to communication stability, particularly in enterprise environments that rely on uninterrupted telephony services. A secondary vulnerability, CVE-2025-20351, carries a medium severity rating with a CVSS score of 6.1. It stems from insufficient input validation in the web UI, allowing attackers to inject malicious scripts via crafted links. Exploitation requires user interaction, such as clicking a link, and can result in stolen session data or UI manipulation. This XSS flaw is tied to bug ID CSCwn51683 and highlights ongoing security concerns in the web handling components of affected firmware. No known public exploits or active attacks have been reported, but organizations using Web Access face elevated risk. Cisco recommends disabling Web Access through CUCM or its Bulk Administration Tool as an immediate mitigation. Security patches are now available in SIP Software versions 3.3(1), 14.3(1)SR2, and 11.0(6)SR7 for the respective device models. Prompt updates are advised to ensure security and maintain service reliability.
Phoenix Contact this week released firmware updates for its QUINT4 uninterruptible power supply (UPS) EtherNet/IP product line to address five vulnerabilities disclosed by CyberDan...
Microsoft has released a critical security update to address what is being described as the most severe vulnerability ever discovered in ASP.NET Core. The flaw, identified as CVE-2...
ConnectWise has issued a major patch to its Automate platform (version 2025.9) to remediate severe security vulnerabilities that could compromise software upgrades. They were found...