Impact
Suricata’s SIP parser stores request and response body lengths in 16-bit fields; bodies larger than 65,536 bytes are truncated, causing frame:request.body and frame:response.body to expose only part of the message. This numeric truncation error (CWE-197) allows content beyond the 65-kilobyte limit to escape rule‑based detection engines, potentially hiding malicious payloads while the rest of the SIP message appears normal. Based on the description, it is inferred that an attacker can send SIP traffic containing a body larger than 65,536 bytes to trigger the truncation.
Affected Systems
The vulnerability affects Suricata that is distributed by the Open Information Security Foundation. Versions 8.0.0 through 8.0.6 are impacted. The issue was addressed in release 8.0.6.
Risk and Exploitability
With a CVSS score of 3.7 the vulnerability is considered moderate. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting a lower likelihood of widespread exploitation at present. Based on the description, it is inferred that the attack does not require authentication and can be performed over the network, allowing an adversary to embed malicious payloads beyond the 65-kilobyte limit and evade frame‑based detection. This limits the impact to detection evasion rather than direct compromise.
OpenCVE Enrichment