Known vulnerabilities in SIP IP Phone Software
Vendor:
Cisco Systems, Inc
Software:
SIP IP Phone Software
Software CPE:
cpe:2.3:a:cisco_systems:sip_ip_phone_software:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
8
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146773 - Missing release of memory after effective lifetime CVE-2026-20281 |
CWE-401 | Medium | 5.0(1), 11.0(6)SR8, 14.4(1)SR3, 14.4(1)SR4 | 02.09.2026 |
SB2026090285 |
||
| #VU117299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-20351 |
CWE-79 | Low | 3.3(1), 11.0(6)SR7, 14.4(1) | 15.10.2025 |
SB20251015155 |
||
| #VU117298 - Stack-based buffer overflow CVE-2025-20350 |
CWE-121 | Medium | 3.3(1), 11.0(6)SR7, 14.3(1)SR2 | 15.10.2025 |
SB20251015155 |
||
| #VU114783 - Exposure of sensitive information to an unauthorized actor CVE-2025-20336 |
CWE-200 | Medium | 3.3(1), 11.0(6)SR7, 14.3(1)SR2 | 04.09.2025 |
SB2025090419 |
||
| #VU114782 - Improper Access Control CVE-2025-20335 |
CWE-284 | Medium | 3.3(1), 11.0(6)SR7, 14.3(1)SR2 | 04.09.2025 |
SB2025090419 |
||
| #VU104102 - Exposure of sensitive information to an unauthorized actor CVE-2025-20158 |
CWE-200 | Low | 3.3(1) | 20.02.2025 |
SB2025022007 |
||
| #VU100092 - Exposure of sensitive information to an unauthorized actor CVE-2024-20445 |
CWE-200 | Medium | 3.2(1), 14.3(1) | 07.11.2024 |
SB2024110785 |
||
| #VU71105 - Improper Authentication CVE-2023-20018 |
CWE-287 | Medium | 11.0.6 SR4, 14.1.1 SR2 | 11.01.2023 |
SB2023011154 |