← Vulnerability feed

Vulnerability record · CVE-2020-16139 · published 12 August 2020

CVE-2020-16139: Cisco Unified IP Conference Station 7937G crafted packet denial of service

Cisco · Unified Ip Conference Station 7937g Firmware

Cisco Unified IP Conference Station 7937G firmware versions 1-4-4-0 through 1-4-5-7 can be restarted remotely by sending specially crafted packets. The vendor notes it cannot prove the vulnerability exists and assigned the CVE out of caution because the product is end of life. A remote restart of a conference station disrupts meetings and availability.

7.5 CVSS 3.1 High EPSS 80% · top 0.4%
7.5CVSS 3.1 base score, v2 7.8
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityHigh CVSS and EPSS, but the vendor states the vulnerability cannot be proven to exist and the product is end of life, limiting real-world exposure.

What it is

Cisco Unified IP Conference Station 7937G firmware versions 1-4-4-0 through 1-4-5-7 can be restarted remotely by sending specially crafted packets. The vendor notes it cannot prove the vulnerability exists and assigned the CVE out of caution because the product is end of life. A remote restart of a conference station disrupts meetings and availability.

Impact

An unauthenticated remote attacker can force the device to restart, causing a denial of service for anyone relying on that conference station. There is no reported loss of confidentiality or integrity, only availability.

Attack surface

The flaw is reachable over the network via crafted packets sent to the device, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

Public exploit references exist (Packet Storm and Black Lantern Security tags), but the CVE is not listed in CISA KEV and no ransomware use is documented. EPSS is high at 0.7977 (99.588th percentile), indicating elevated predicted exploitation activity.

What to do

  • Retire or replace the end-of-life Cisco 7937G; Cisco's end-of-life notice is the authoritative guidance.
  • If the device cannot be removed immediately, isolate it on a dedicated voice VLAN with strict ACLs limiting access to trusted call-control hosts only.
  • Block or filter crafted packet traffic to the device at network boundaries and monitor for abnormal restart patterns.
  • Track the device inventory so any remaining 7937G units are known and prioritized for removal.

Detection

  • Monitor device syslog or SNMP traps for unexpected restarts or reboots of 7937G conference stations.
  • Alert on network traffic to the conference station from hosts outside the expected call-control subnet.
  • Baseline normal packet patterns to the device and flag anomalies consistent with crafted packet floods.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-16139 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2020-16139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.