Record summary

CVE-2020-16139 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 11, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

unified_ip_conference_station_7937g_firmware

Browse Cisco / unified_ip_conference_station_7937g_firmware

Default status: unknown

VulnCheck, CVE List1.4.4.0 to ≤ 1.4.5.7affected

Proofs of concept

1

Catalogued exploits

MetasploitCisco 7937G Denial-of-Service Reboot AttackMetasploit auxiliary PoCby Cody MartinNot analyzed1 file

Ruby

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHCisco Unified IP Conference Station 7937G - Denial-of-ServiceCVSS 7.5

Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to restart the device remotely via specially crafted packets that can cause a denial-of-service condition. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded.

Impact

An attacker can exploit this vulnerability to disrupt the functionality of the conference station, leading to a denial of service for legitimate users.

Remediation

Apply the latest firmware update provided by Cisco to mitigate this vulnerability.

Authorspikpikcu
Template tagscvecve2020dosciscopacketstormvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:o:cisco:unified_ip_conference_station_7937g_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4