Vulnerabilities > CVE-2006-0368 - Remote Denial Of Service vulnerability in Cisco CallManager
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
COMPLETE Summary
Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.
Vulnerable Configurations
References
- http://secunia.com/advisories/18494
- http://securityreason.com/securityalert/359
- http://securitytracker.com/id?1015503
- http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtml
- http://www.osvdb.org/22622
- http://www.osvdb.org/22623
- http://www.securityfocus.com/bid/16295
- http://www.vupen.com/english/advisories/2006/0249
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24180