CVE-2025-20165
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 22, 2025
CWE ID 789
CWE ID 476
Summary
CVE-2025-20165 is a vulnerability affecting the SIP processing subsystem of Cisco BroadWorks. This issue permits unauthenticated, remote attackers to cause a denial of service (DoS) by sending a large number of SIP requests. The vulnerability arises from improper memory handling in processing certain SIP requests, leading to memory exhaustion on affected Cisco BroadWorks Network Servers. The servers, once out of memory, can no longer process incoming requests, causing a DoS condition that necessitates manual intervention to recover.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.