CVE-2025-20165
published 2025-01-22CVE-2025-20165: A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.83%
53.2th percentile
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper memory handling for certain SIP requests. An attacker could exploit this vulnerability by sending a high number of SIP requests to an affected system. A successful exploit could allow the attacker to exhaust the memory that was allocated to the Cisco BroadWorks Network Servers that handle SIP traffic. If no memory is available, the Network Servers can no longer process incoming requests, resulting in a DoS condition that requires manual intervention to recover.
Affected
2701 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | broadworks_network_server | < 2024.11 | 2024.11 |
| cisco | broadworks_sip | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
| cisco | cisco_broadworks | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco BroadWorks SIP Denial of Service Vulnerability
vendor_cisco·2025-01-22·CVSS 7.5
CVE-2025-20165 [HIGH] CWE-789 Cisco BroadWorks SIP Denial of Service Vulnerability
Cisco BroadWorks SIP Denial of Service Vulnerability
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper memory handling for certain SIP requests. An attacker could exploit this vulnerability by sending a high number of SIP requests to an affected system. A successful exploit could allow the attacker to exhaust the memory that was allocated to the Cisco BroadWorks Network Servers that handle SIP traffic. If no memory is available, the Network Servers can no longer process incoming requests, resulting in a DoS condition that requires manual intervention to recover.
For more information abou
Cisco
Cisco BroadWorks SIP Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20165 Cisco BroadWorks SIP Denial of Service Vulnerability
CVE-2025-20165: Cisco BroadWorks SIP Denial of Service Vulnerability
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition. This vulnerability is due to improper memory handling for certain SIP requests. An attacker could exploit this vulnerability by sending a high number of SIP requests to an affected system. A successful exploit could allow the attacker to exhaust the memory that was allocated to the Cisco BroadWorks Network Servers that handle SIP traffic. If no memory is available, the Network Servers can no longer process incoming requests, resulting in a DoS condition that requires manual intervention to recover. For more inf
GHSA
GHSA-gxvq-f5q4-6g92: A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming
ghsa_unreviewed·2025-01-22
CVE-2025-20165 [HIGH] CWE-476 GHSA-gxvq-f5q4-6g92: A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper memory handling for certain SIP requests. An attacker could exploit this vulnerability by sending a high number of SIP requests to an affected system. A successful exploit could allow the attacker to exhaust the memory that was allocated to the Cisco BroadWorks Network Servers that handle SIP traffic. If no memory is available, the Network Servers can no longer process incoming requests, resulting in a DoS condition that requires manual intervention to recover.
No detection rules found.
No public exploits indexed.
2025-01-22
Published