CVE-2026-0710
8.4SIPp · SIPp
A NULL pointer dereference vulnerability in SIPp allows remote attackers to cause a denial of service or potentially execute unauthorized code via crafted SIP messages.
Executive summary
A critical vulnerability in SIPp allows remote attackers to crash the application or achieve code execution, posing a severe threat to system integrity and availability.
Vulnerability
This is a NULL pointer dereference vulnerability triggered by sending specially crafted Session Initiation Protocol (SIP) messages during an active call. The vulnerability can be triggered by an unauthenticated remote attacker.
Business impact
The exploitation of this flaw can result in a complete denial of service for the affected SIPp instance, disrupting critical communication flows. Given the CVSS score of 8.4, the potential for unauthorized code execution presents a high risk of total system compromise, leading to data loss or further lateral movement within the network.
Remediation
Immediate Action: Organizations should restrict access to SIPp services to trusted networks and monitor for official vendor patches to address the NULL pointer dereference.
Proactive Monitoring: Security teams should monitor system logs for frequent application crashes or unexpected service restarts which may indicate active exploitation attempts.
Compensating Controls: Deploy network intrusion detection signatures capable of identifying malformed or anomalous SIP traffic patterns to block malicious payloads before they reach the application.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention, particularly in environments where SIPp is exposed to untrusted network traffic. Administrators must prioritize the implementation of defensive network controls and remain vigilant for vendor-supplied updates to fully remediate the underlying code defect.
More SIPp CVEs
Sources
Originally found and disclosed by Red Hat would like to thank ChenYiFan Liu, Fanny-wen, and Zhoufan Wen for reporting this issue., per the CVE Program record.
- Vulnerability database entry
- RHBZ#2427788 Issue tracker