Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.
Conclusion & alert: CVE-2006-0368 is rated Moderate Risk (62.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 3.64%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.75% | 3.64% | +0.89% |
| 2 | 2025-06-23 | 2.76% | 2.75% | -0.01% |
| 3 | 2025-03-30 | — | 2.76% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 2.0 | HIGH |
|
10.0 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cisco | call_manager | — | cpe:2.3:h:cisco:call_manager:*:*:*:*:*:*:*:* |
| cisco | call_manager | 1.0 | cpe:2.3:h:cisco:call_manager:1.0:*:*:*:*:*:*:* |
| cisco | call_manager | 2.0 | cpe:2.3:h:cisco:call_manager:2.0:*:*:*:*:*:*:* |
| cisco | call_manager | 3.0 | cpe:2.3:h:cisco:call_manager:3.0:*:*:*:*:*:*:* |
| cisco | call_manager | 3.1 | cpe:2.3:h:cisco:call_manager:3.1:*:*:*:*:*:*:* |
| cisco | call_manager | 3.1\(2\) | cpe:2.3:h:cisco:call_manager:3.1\(2\):*:*:*:*:*:*:* |
| cisco | call_manager | 3.1\(3a\) | cpe:2.3:h:cisco:call_manager:3.1\(3a\):*:*:*:*:*:*:* |
| cisco | call_manager | 3.2 | cpe:2.3:h:cisco:call_manager:3.2:*:*:*:*:*:*:* |
| cisco | call_manager | 3.3 | cpe:2.3:h:cisco:call_manager:3.3:*:*:*:*:*:*:* |
| cisco | call_manager | 3.3\(3\) | cpe:2.3:h:cisco:call_manager:3.3\(3\):*:*:*:*:*:*:* |
| cisco | call_manager | 3.3\(3\)es61 | cpe:2.3:h:cisco:call_manager:3.3\(3\)es61:*:*:*:*:*:*:* |
| cisco | call_manager | 3.3\(4\)es25 | cpe:2.3:h:cisco:call_manager:3.3\(4\)es25:*:*:*:*:*:*:* |
| cisco | call_manager | 3.3\(5\) | cpe:2.3:h:cisco:call_manager:3.3\(5\):*:*:*:*:*:*:* |
| cisco | call_manager | 3.3\(5\)es30 | cpe:2.3:h:cisco:call_manager:3.3\(5\)es30:*:*:*:*:*:*:* |
| cisco | call_manager | 4.0 | cpe:2.3:h:cisco:call_manager:4.0:*:*:*:*:*:*:* |
| cisco | call_manager | 4.0\(2a\)es40 | cpe:2.3:h:cisco:call_manager:4.0\(2a\)es40:*:*:*:*:*:*:* |
| cisco | call_manager | 4.0\(2a\)es62 | cpe:2.3:h:cisco:call_manager:4.0\(2a\)es62:*:*:*:*:*:*:* |
| cisco | call_manager | 4.0\(2a\)sr2b | cpe:2.3:h:cisco:call_manager:4.0\(2a\)sr2b:*:*:*:*:*:*:* |
| cisco | call_manager | 4.1\(2\)es33 | cpe:2.3:h:cisco:call_manager:4.1\(2\)es33:*:*:*:*:*:*:* |
| cisco | call_manager | 4.1\(2\)es55 | cpe:2.3:h:cisco:call_manager:4.1\(2\)es55:*:*:*:*:*:*:* |
| cisco | call_manager | 4.1\(3\)es07 | cpe:2.3:h:cisco:call_manager:4.1\(3\)es07:*:*:*:*:*:*:* |
| cisco | call_manager | 4.1\(3\)es32 | cpe:2.3:h:cisco:call_manager:4.1\(3\)es32:*:*:*:*:*:*:* |
| cisco | call_manager | 4.1\(3\)sr1 | cpe:2.3:h:cisco:call_manager:4.1\(3\)sr1:*:*:*:*:*:*:* |