Impact
SIPp versions up to 3.7.7 contain a buffer overflow in the get_peer_tag() function when parsing SIP To headers whose tag parameters are 2049 bytes or longer. This overflow does not grant code execution but triggers a crash of the SIPp process, resulting in service interruption. The flaw is a classic CWE-120 "Buffer Copy without Length Checks" vulnerability.
Affected Systems
Vulnerable versions include SIPp 3.7.7 and all earlier releases. The offending code resides in the official SIPp distribution and is fixed in subsequent releases.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can remotely trigger the overflow by sending a SIP message with an oversized tag parameter to the SIP interface used by SIPp. No elevated privileges or special configuration are required, so the risk of denial‑of‑service attacks remains significant for unpatched deployments.
OpenCVE Enrichment