Impact
SIPp versions through 3.7.7 contain a buffer overflow in the get_peer_tag() function that processes SIP To header tag values. When an attacker sends a SIP message with a tag parameter that is 2049 bytes or longer, the static buffer is exceeded, causing the SIPp process to crash. The overflow does not immediately grant executable code but can be used for denial-of-service attacks to bring the service down.
Affected Systems
The affected vendor is SIPp. The product is SIPp distributed from the official SIPp project. Versions up to and including 3.7.7 are vulnerable; later releases contain the fix.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, but the KEV status shows it is not listed as a known exploited vulnerability. The attack vector is remote; an unauthenticated attacker can trigger the overflow by sending crafted SIP messages from an external network. Exploit requirements are minimal: access to the SIP interface used by SIPp. Given the high CVSS and the potential for widespread denial of service, this vulnerability poses a significant risk to services using an unpatched SIPp installation.
OpenCVE Enrichment