Vulnerability record · CVE-2020-16139 · published 12 August 2020
CVE-2020-16139: Cisco Unified IP Conference Station 7937G crafted packet denial of service
Cisco · Unified Ip Conference Station 7937g Firmware
Cisco Unified IP Conference Station 7937G firmware versions 1-4-4-0 through 1-4-5-7 can be restarted remotely by sending specially crafted packets. The vendor notes it cannot prove the vulnerability exists and assigned the CVE out of caution because the product is end of life. A remote restart of a conference station disrupts meetings and availability.
Description
A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityHigh CVSS and EPSS, but the vendor states the vulnerability cannot be proven to exist and the product is end of life, limiting real-world exposure.
What it is
Cisco Unified IP Conference Station 7937G firmware versions 1-4-4-0 through 1-4-5-7 can be restarted remotely by sending specially crafted packets. The vendor notes it cannot prove the vulnerability exists and assigned the CVE out of caution because the product is end of life. A remote restart of a conference station disrupts meetings and availability.
Impact
An unauthenticated remote attacker can force the device to restart, causing a denial of service for anyone relying on that conference station. There is no reported loss of confidentiality or integrity, only availability.
Attack surface
The flaw is reachable over the network via crafted packets sent to the device, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Public exploit references exist (Packet Storm and Black Lantern Security tags), but the CVE is not listed in CISA KEV and no ransomware use is documented. EPSS is high at 0.7977 (99.588th percentile), indicating elevated predicted exploitation activity.
What to do
- Retire or replace the end-of-life Cisco 7937G; Cisco's end-of-life notice is the authoritative guidance.
- If the device cannot be removed immediately, isolate it on a dedicated voice VLAN with strict ACLs limiting access to trusted call-control hosts only.
- Block or filter crafted packet traffic to the device at network boundaries and monitor for abnormal restart patterns.
- Track the device inventory so any remaining 7937G units are known and prioritized for removal.
Detection
- Monitor device syslog or SNMP traps for unexpected restarts or reboots of 7937G conference stations.
- Alert on network traffic to the conference station from hosts outside the expected call-control subnet.
- Baseline normal packet patterns to the device and flag anomalies consistent with crafted packet floods.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158819/Cisco-7937G-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.blacklanternsecurity.com/2020-08-07-Cisco-Unified-IP-Conference-Station-7937G/ | ExploitThird Party Advisory |
| https://www.cisco.com/c/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7940g/end_of_life_notice_c51- | Vendor Advisory |
| http://packetstormsecurity.com/files/158819/Cisco-7937G-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.blacklanternsecurity.com/2020-08-07-Cisco-Unified-IP-Conference-Station-7937G/ | ExploitThird Party Advisory |
| https://www.cisco.com/c/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7940g/end_of_life_notice_c51- | Vendor Advisory |
Track CVE-2020-16139 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-16139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.