Can someone help me to provide information about the given below sessions between IP Phone and CUCM Publisher and Subscriber. Why source and destination both ports are higher and what kind of communication happens during the sessions. As i have reply to security team about this communication.
Your looking for the services that use the ephemeral ports.
It's probably TFTP from the phones requesting config info from the CUCM servers. You can check for sure with a packet capture on the phones though.
As per the document, ephemeral ports start from 32768 but as you can see in screen shot, sessions are using 16000 port too.
The ephemeral port range for the system is 32768 to 61000.