cbcvebase.
CVE-2006-0368
published 2006-01-22

CVE-2006-0368: Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of…

PriorityP427high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.72%
88.5th percentile
Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.

Affected

23 ranges
VendorProductVersion rangeFixed in
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
ciscocall_manager
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.