Impact
sngrep, a network traffic monitoring tool, contains an unchecked stack buffer in its SIP attribute formatting routines. When SIP header values exceed the 255‑byte limit, the application can overflow the stack while parsing incoming packets. An attacker can craft SIP packets with oversized Call‑ID, X‑Call‑ID, or other header fields, causing the process to crash or potentially execute arbitrary code during rendering.
Affected Systems
The flaw affects irontec sngrep version 1.8.4. Any deployment that receives or processes SIP traffic with this version is susceptible to the overflow.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. EPSS data indicates a very low exploitation probability (< 1 %), yet the flaw is reachable over the network and does not require local privileges. The issue is not listed in the CISA KEV catalog, but the combination of high severity and network accessibility makes timely remediation essential.
OpenCVE Enrichment