Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-16137

Опубликовано: 12 авг. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 6.8
EPSS Высокий

Описание

A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:unified_ip_conference_station_7937g_firmware:*:*:*:*:*:*:*:*
Версия от 1.4.4.0 (включая) до 1.4.5.7 (включая)
cpe:2.3:h:cisco:unified_ip_conference_station_7937g:-:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.73245
Высокий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information.

EPSS

Процентиль: 99%
0.73245
Высокий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo