CVE-2019-1922: Cisco IP Conference Phone 7832 Firmware

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.

Affected products

  • Cisco IP Conference Phone 7832 Firmware: affected versions not specified
  • Cisco IP Conference Phone 8832 Firmware: version 11.5(1) only; version 12.5(1) only
  • Cisco IP Phone 7811 Firmware: affected versions not specified
  • Cisco IP Phone 7821 Firmware: affected versions not specified
  • Cisco IP Phone 7841 Firmware: affected versions not specified
  • Cisco IP Phone 7861 Firmware: affected versions not specified
  • Cisco IP Phone 8811 Firmware: version 11.5(1) only; version 12.5(1) only
  • Cisco IP Phone 8841 Firmware: version 11.5(1) only; version 12.5(1) only
  • Cisco IP Phone 8845 Firmware: version 11.5(1) only; version 12.5(1) only
  • Cisco IP Phone 8851 Firmware: version 11.5(1) only; version 12.5(1) only
  • Cisco IP Phone 8861 Firmware: version 11.5(1) only; version 12.5(1) only
  • Cisco IP Phone 8865 Firmware: version 11.5(1) only; version 12.5(1) only

Published 2019-07-06. Last modified 2026-06-17.