SIP Signaling Vulnerability in Verizon IMS
CVE-2026-10629

7.4HIGH

Key Information:

Vendor

Verizon

Status
Vendor
CVE Published:
2 June 2026

What is CVE-2026-10629?

The SIP signaling stack in Verizon's IMS is susceptible to security issues due to the absence of IPsec integrity protection. This flaw allows an attacker to exploit unsecured SIP messages, compromising the confidentiality, integrity, and authenticity of Voice over LTE (VoLTE) signaling. Attackers can potentially intercept and manipulate SIP messages during their transmission over both radio and core network paths, posing significant risks to communication security.

Affected Version(s)

VoLTE UNKNOWN

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.