Both sccp ports (tcp ports 2000 and 2443) are used by Cisco CallManager systems employing Cisco's proprietary SCCP protocol.

A cisco callmanager system that employs cisco's proprietary sccp protocol will typically respond on tcp ports 2000-2002.

The attack vector for exploitation is through a skinny client control protocol (sccp) packet using tcp port 2000.

Cisco has released software updates that address this vulnerability.

I recently migrated a pair of atms from behind a microsoft threat management gateway to a cisco asa.

The skinny call control protocol (sccp) implementation in cisco unified callmanager (cucm) 3.3 before 3.3(5)sr2a, 4.1 before 4.1(3)sr4, 4.2 before 4.2(3)sr1, and 5.0 before 5.0(4a)su1 allows remote attackers to cause a denial of service (loss of voice services) by sending crafted packets to the (1) sccp (2000/tcp) or (2) sccps (2443/tcp) port. Filtered) port state service 23/tcp. The exploit database is a cve compliant archive of public exploits and corresponding vulnerable software, developed for use by penetration testers and vulnerability researchers.