Port 8002CUCM Intercluster
Port 8002 is used by Cisco Unified Communications Manager (CUCM) for intercluster communication, facilitating seamless voice and call control information exchange between different CUCM clusters deployed within an organization..
- transport
- tcp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 10,576
single transport
payload readable on path
used by convention
caution
rank 413 of 993 · top 42%
Technical Details
what runs on :8002Cisco Unified Communications Manager (CUCM) is a highly scalable, IP-based communications system that provides voice, video, messaging, and mobility capabilities. Port 8002 specifically serves as an intercluster signaling port, allowing distinct CUCM clusters to communicate in multi-cluster deployments. This enables features like call routing, directory lookups, user presence sharing, and intercluster trunk connections, which are essential for large enterprises with distributed call control domains.
Intercluster communication facilitates call setup, teardown, and supplementary services such as call transfer and conferencing between clusters. Signaling on port 8002 typically uses Cisco’s proprietary protocols encapsulated over TCP, ensuring reliable session establishment and management. Proper functioning of this port is critical for maintaining uninterrupted collaboration across geographically dispersed sites.
Network administrators must ensure that port 8002 remains reachable across firewall boundaries where intercluster features are needed. While this port is primarily unofficial, it’s widely recognized in Cisco VoIP deployments. Non-standard ports and proprietary protocols should be documented and monitored to ensure interoperability and support.
Security Information
exposure of :8002risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
tcp
every listening transport is another surface to filter at the edge
security overview
Common vulnerabilities include:
- Unauthorized access through insufficiently protected intercluster links, enabling attackers to inject or intercept signaling traffic.
- Exploitation of proprietary protocols over this port if unencrypted, leading to data leakage or signaling manipulation.
- Denial-of-Service (DoS) attacks targeting port 8002, disrupting call signaling and intercluster connectivity.
Mitigations involve:
- Enforcing strong mutual authentication between clusters, often achieved via certificates and secure trunk configurations.
- Using IPsec or TLS tunnels to encrypt intercluster signaling where supported to protect sensitive call data.
- Implementing strict firewall rules to restrict access solely to trusted CUCM cluster IP addresses.
- Continuously monitoring traffic for anomalies, unauthorized access attempts, or unusual signaling patterns to detect potential breaches.
- Keeping Cisco UC infrastructure updated with security patches to mitigate protocol or software vulnerabilities.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted