OpenSIPS has vulnerability in the building the local negative replies
CVE-2023-28095

7.5HIGH

Key Information:

Vendor

Opensips

Status
Vendor
CVE Published:
15 March 2023

What is CVE-2023-28095?

OpenSIPS, a widely used Session Initiation Protocol (SIP) server, has a vulnerability in the msg_translator.c file that could potentially lead to a server crash. Although this issue was identified during fuzz testing and pertains to the function build_res_buf_from_sip_req, it could not be replicated against an active OpenSIPS instance. Importantly, no public functions were linked to this vulnerability, rendering exploitation extremely improbable. Should exploitation occur through undiscovered methods, it is anticipated to result solely in Denial of Service. The vulnerability has been resolved in OpenSIPS versions 3.1.7 and 3.2.4.

Affected Version(s)

opensips < 3.1.7 < 3.1.7

opensips >= 3.2.0, < 3.2.4 < 3.2.0, 3.2.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.