CVE-2006-0368
published 2006-01-22CVE-2006-0368: Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of…
PriorityP427high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.72%
88.5th percentile
Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Call Manager Denial of Service
vendor_cisco·2006-01-18
CVE-2006-0368 CWE-399 Cisco Call Manager Denial of Service
Cisco Call Manager Denial of Service
Cisco CallManager (CCM) is the software-based call-processing component
of the Cisco IP telephony solution which extends enterprise telephony features
and functions to packet telephony network devices such as IP phones, media
processing devices, voice-over-IP (VoIP) gateways, and multimedia applications.
All Cisco CallManager versions are vulnerable to these Denial of Service (DoS)
attacks, which may result in services being interrupted or servers rebooting.
Cisco has made free software available to address this vulnerability
for affected customers. There are network-based workarounds available to
mitigate the effects of the vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-
Cisco
Cisco Call Manager Denial of Service
vendor_cisco
CVE-2006-0368 Cisco Call Manager Denial of Service
CVE-2006-0368: Cisco Call Manager Denial of Service
Cisco CallManager (CCM) is the software-based call-processing component of the Cisco IP telephony solution which extends enterprise telephony features and functions to packet telephony network devices such as IP phones, media processing devices, voice-over-IP (VoIP) gateways, and multimedia applications. All Cisco CallManager versions are vulnerable to these Denial of Service (DoS) attacks, which may result in services being interrupted or servers rebooting. Cisco has made free software available to address this vulnerability for affected customers. There are network-based
CWE: CWE-399, CWE-399
Bug IDs: CSCea53907, CSCsa86197, CSCsb16635, CSCsb64161
GHSA
GHSA-p4h8-95wc-cxcp: Cisco CallManager 3
ghsa_unreviewed·2022-05-01
CVE-2006-0368 [HIGH] GHSA-p4h8-95wc-cxcp: Cisco CallManager 3
Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/18494http://securityreason.com/securityalert/359http://securitytracker.com/id?1015503http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtmlhttp://www.osvdb.org/22622http://www.osvdb.org/22623http://www.securityfocus.com/bid/16295http://www.vupen.com/english/advisories/2006/0249https://exchange.xforce.ibmcloud.com/vulnerabilities/24180http://secunia.com/advisories/18494http://securityreason.com/securityalert/359http://securitytracker.com/id?1015503http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtmlhttp://www.osvdb.org/22622http://www.osvdb.org/22623http://www.securityfocus.com/bid/16295http://www.vupen.com/english/advisories/2006/0249https://exchange.xforce.ibmcloud.com/vulnerabilities/24180
2006-01-22
Published