Port 8002CUCM Intercluster

Port 8002 is used by Cisco Unified Communications Manager (CUCM) for intercluster communication, facilitating seamless voice and call control information exchange between different CUCM clusters deployed within an organization..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
10,576

rank 413 of 993 · top 42%

Technical Details

what runs on :8002

Cisco Unified Communications Manager (CUCM) is a highly scalable, IP-based communications system that provides voice, video, messaging, and mobility capabilities. Port 8002 specifically serves as an intercluster signaling port, allowing distinct CUCM clusters to communicate in multi-cluster deployments. This enables features like call routing, directory lookups, user presence sharing, and intercluster trunk connections, which are essential for large enterprises with distributed call control domains.

Intercluster communication facilitates call setup, teardown, and supplementary services such as call transfer and conferencing between clusters. Signaling on port 8002 typically uses Cisco’s proprietary protocols encapsulated over TCP, ensuring reliable session establishment and management. Proper functioning of this port is critical for maintaining uninterrupted collaboration across geographically dispersed sites.

Network administrators must ensure that port 8002 remains reachable across firewall boundaries where intercluster features are needed. While this port is primarily unofficial, it’s widely recognized in Cisco VoIP deployments. Non-standard ports and proprietary protocols should be documented and monitored to ensure interoperability and support.

Security Information

exposure of :8002

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common vulnerabilities include:

  • Unauthorized access through insufficiently protected intercluster links, enabling attackers to inject or intercept signaling traffic.
  • Exploitation of proprietary protocols over this port if unencrypted, leading to data leakage or signaling manipulation.
  • Denial-of-Service (DoS) attacks targeting port 8002, disrupting call signaling and intercluster connectivity.

Mitigations involve:

  • Enforcing strong mutual authentication between clusters, often achieved via certificates and secure trunk configurations.
  • Using IPsec or TLS tunnels to encrypt intercluster signaling where supported to protect sensitive call data.
  • Implementing strict firewall rules to restrict access solely to trusted CUCM cluster IP addresses.
  • Continuously monitoring traffic for anomalies, unauthorized access attempts, or unusual signaling patterns to detect potential breaches.
  • Keeping Cisco UC infrastructure updated with security patches to mitigate protocol or software vulnerabilities.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted