CVE-2020-16139
Cisco Unified IP Conference Station 7937G Crafted Packets Remote Denial of Service
Record summary
CVE-2020-16139 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 11, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
unified_ip_conference_station_7937g_firmwareBrowse Cisco / unified_ip_conference_station_7937g_firmwareDefault status: unknown | VulnCheck, CVE List | 1.4.4.0 to ≤ 1.4.5.7 | affected |
Proofs of concept
1Catalogued exploits
MetasploitCisco 7937G Denial-of-Service Reboot AttackMetasploit auxiliary PoCby Cody MartinNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHCisco Unified IP Conference Station 7937G - Denial-of-ServiceCVSS 7.5
Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to restart the device remotely via specially crafted packets that can cause a denial-of-service condition. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded.
Impact
An attacker can exploit this vulnerability to disrupt the functionality of the conference station, leading to a denial of service for legitimate users.
Remediation
Apply the latest firmware update provided by Cisco to mitigate this vulnerability.
Source: ProjectDiscovery