Impact
SIPSorcery, a WebRTC, SIP, and VoIP library for C# and .NET, has an input validation flaw in the RTPChannel.OnRTPPacketReceived and the STUN attribute parsing routines. Untrusted packet data is indexed without adequate length checks, which can trigger an index‑out‑of‑bounds exception. Because UdpReceiver.EndReceiveFrom closes the channel whenever a non‑socket exception occurs, the effect is an abrupt termination of an active RTP or WebRTC media session. The attack requires only knowledge of the advertised UDP port and no authentication, limiting the impact to availability.
Affected Systems
The vulnerability is present in any version of sipsorcery before 10.0.9. Any deployment that uses the SIPSorcery library for real‑time media will be impacted if the RTP/ICE socket is exposed to unknown network participants.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity. The EPSS score is < 1%, so the likelihood of exploitation at this time is low, but the fact that no authentication is required and the attack requires only knowledge of the advertised UDP port makes it a realistic threat. The vulnerability is not currently listed CISA’s KEV catalog, so no public exploits are documented, but since attackers do not need to authenticate and only need knowledge of the advertised UDP port, this remote attack can pose a real risk if the port is reachable from the broader internet.
OpenCVE Enrichment
Github GHSA