CVE 6.1 MEDIUM

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware Cross-Site Scripting Vulnerability_CVE-2025-20351

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running Cisco SIP Software could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of the web UI.

This vulnerability exists because the web UI of an affected device does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Note: To exploit this vulnerability, the phone must be registered to Cisco Unified Communications Manager and have Web Access enabled. Web Access is disabled by default.

Basic Information

ID CVE-2025-20351
Source cisco
Published Oct 15, 2025 at 16:15
Modified Oct 15, 2025 at 17:43

Affected Product

Vendor Cisco
Product Cisco Session Initiation Protocol (SIP) Software
Version 12.1(1)SR1
Affected Versions Cisco Cisco Session Initiation Protocol (SIP) Software 12.1(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.5(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(2)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.2(2)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR4
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.4(1)SR2 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 11.7(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 12.1(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(0.7) MPP
Cisco Cisco Session Initiation Protocol (SIP) Software 9.3(4) 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 12.5(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 10.2(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 9.3(4)SR3 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 10.2(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 12.5(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 11-0-1MSR1-1
Cisco Cisco Session Initiation Protocol (SIP) Software 10.4(1) 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 12.5(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.5(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 10.1(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 12.0(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 12.6(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1.11) 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 12.0(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 12.0(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 9.3(3)
Cisco Cisco Session Initiation Protocol (SIP) Software 12.5(1)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR4b
Cisco Cisco Session Initiation Protocol (SIP) Software 9.3(4)SR1 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR5
Cisco Cisco Session Initiation Protocol (SIP) Software 10.1(1.9)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1.9) 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 9.3(4)SR2 3rd Party
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 10.1(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 12.0(1)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 12.6(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 12.7(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR6
Cisco Cisco Session Initiation Protocol (SIP) Software 12.8(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 12.7(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(2)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(4)
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(2)
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(4)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(5)
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(3)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(3)SR4
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(3)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(2)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(4)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(5)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(3)
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(5)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(3)SR6
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(5)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(4)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(3)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(3)SR5
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(6)
Cisco Cisco Session Initiation Protocol (SIP) Software 12.8(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 12.8(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 14.0(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 14.0(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(6)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 10.3(1)SR7
Cisco Cisco Session Initiation Protocol (SIP) Software 14.0(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 14.1(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 14.0(1)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(6)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 14.1(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 14.1(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(6)SR4
Cisco Cisco Session Initiation Protocol (SIP) Software 14.2(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 14.2(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(6)SR5
Cisco Cisco Session Initiation Protocol (SIP) Software 14.1(1)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 14.2(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 3.1(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 3.0(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 2.3(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 2.3(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 2.2(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 2.1(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 2.0(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 14.2(1)SR3
Cisco Cisco Session Initiation Protocol (SIP) Software 3.1(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 14.3(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 3.2(1)
Cisco Cisco Session Initiation Protocol (SIP) Software 14.3(1)SR1
Cisco Cisco Session Initiation Protocol (SIP) Software 14.2(1)SR4
Cisco Cisco Session Initiation Protocol (SIP) Software 11.0(6)SR6
Cisco Cisco Session Initiation Protocol (SIP) Software 14.3(1)SR2
Cisco Cisco Session Initiation Protocol (SIP) Software 14.3(1)SR3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.