Vulnerability Name: | CVE-2006-0368 (CCN-24180) | ||||||||
Assigned: | 2006-01-18 | ||||||||
Published: | 2006-01-18 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0368 Source: CCN Type: SA18494 Cisco CallManager Connection Handling Denial of Service Source: SECUNIA Type: Patch, Vendor Advisory 18494 Source: SREASON Type: UNKNOWN 359 Source: CCN Type: SECTRACK ID: 1015503 Cisco CallManager TCP Connection Management Handling Lets Remote Users Deny Service Source: SECTRACK Type: UNKNOWN 1015503 Source: CCN Type: Cisco CallManager Web page Introduction Source: CCN Type: cisco-sa-20060118-ccmdos Cisco Security Advisory: Cisco Call Manager Denial of Service Source: CISCO Type: UNKNOWN 20060118 Cisco Call Manager Denial of Service Source: OSVDB Type: UNKNOWN 22622 Source: OSVDB Type: UNKNOWN 22623 Source: CCN Type: OSVDB ID: 22622 Cisco CallManager Port 2000 Connection Saturation Resource Consumption DoS Source: CCN Type: OSVDB ID: 22623 Cisco CallManager Connection Saturation Window Message Queue Exhaustion DoS Source: BID Type: UNKNOWN 16295 Source: CCN Type: BID-16295 Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-0249 Source: XF Type: UNKNOWN cisco-callmanager-port-connection-dos(24180) Source: XF Type: UNKNOWN cisco-callmanager-port-connection-dos(24180) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |