Impact
An issue in Kamailio versions 6.1.1 and earlier allows a remote attacker to manipulate the IMS P‑CSCF registration handling components in a way that causes the SIP proxy to crash. The vulnerability results in a denial of service, interrupting VoIP communications for the affected systems. It falls under improper input validation and resource exhaustion weaknesses.
Affected Systems
The affected product is Kamailio 6.1.1 and all prior releases. The vulnerability is identified in the IMS P‑CSCF registration handling components of the SIP proxy.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation. The CVSS score of 7.5 signals a medium‑high severity. The vulnerability is not listed in CISA KEV, but it can cause a denial of service on any network running Kamailio 6.1.1 or earlier. The description suggests a remote attacker could use crafted IMS P‑CSCF registration messages to trigger a crash; however, the documentation does not state that authentication or privileged access is required, so it is inferred that it may be an unauthenticated attack. The potential impact is loss of service for all users of the SIP proxy and a severe degradation of VoIP availability.
OpenCVE Enrichment
Debian DSA