CRITICAL

CVE-2020-16137

CVSS v3

9.8

CRITICAL

EPSS Score

73.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

Technical details

Published
8/12/2020

Frequently asked questions

What is CVE-2020-16137?

A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

Is CVE-2020-16137 actively exploited?

Active exploitation of CVE-2020-16137 has not been confirmed. The EPSS score is 73.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-16137?

CVE-2020-16137 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-16137 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.