Vulnerabilities
Vulnerable Software
Kamailio:  >> Kamailio  >> 5.1.7  Security Vulnerabilities
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-03-15
Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters. This occurs in the remove_hf function in the Kamailio textops module. Particular use of remove_hf in Sippy Softswitch may allow skilled attacker having a valid credential in the system to disrupt internal call start/duration accounting mechanisms leading potentially to a loss of revenue.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-11-18


Contact Us

Shodan ® - All rights reserved