Impact
SIPp through version 3.7.7 includes a stack buffer overflow in the createAuthHeader() routine that is triggered when processing SIP authentication challenges with oversized algorithm parameters. The vulnerability can be exercised by a malicious SIP server sending a crafted 401 or 407 challenge. The overflow corrupts the client’s stack and leads to a crash, resulting in a denial‑of‑service outcome.
Affected Systems
The affected product is SIPp, the open‑source SIP testing tool. All releases up to and including version 3.7.7 are vulnerable; newer releases patch the issue.
Risk and Exploitability
The CVSS score is 8.7, indicating a severe vulnerability. The EPSS score is < 1%, and the CVE is not listed in the CISA KEV catalogue, so the exact exploitation likelihood is unknown, but the vulnerability can be triggered by any SIP server that the client communicates with. An attacker with network visibility can send a crafted challenge to a vulnerable SIPp client to force a crash and disrupt service.
OpenCVE Enrichment