Impact
A vulnerability in Kamailio versions 6.1.1 and earlier allows a remote attacker to cause a denial of service by sending a malformed IMS registration or security‑agreement message that triggers a crash in the ims_registrar_pcscf module, specifically during pcscf_save_pending or when parsing the security‑agreement in sec_agree.c.
Affected Systems
The affected product is the Kamailio SIP server, versions 6.1.1 and all earlier releases; later versions are not known to contain the flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of <1% signals a low exploitation likelihood. The vulnerability is not listed in CISA KEV. The flaw can be exploited remotely by an attacker able to send crafted IMS traffic, but no public exploits are known, so the risk remains moderate to high for environments relying on continuous service.
OpenCVE Enrichment
Debian DSA