Vulnerability Details CVE-2022-31002
Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a patch for this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2022-31002
-
cpe:2.3:a:signalwire:sofia-sip:1.11.0
-
cpe:2.3:a:signalwire:sofia-sip:1.11.1
-
cpe:2.3:a:signalwire:sofia-sip:1.11.2
-
cpe:2.3:a:signalwire:sofia-sip:1.11.3
-
cpe:2.3:a:signalwire:sofia-sip:1.11.4
-
cpe:2.3:a:signalwire:sofia-sip:1.11.5
-
cpe:2.3:a:signalwire:sofia-sip:1.11.6
-
cpe:2.3:a:signalwire:sofia-sip:1.11.7
-
cpe:2.3:a:signalwire:sofia-sip:1.11.8
-
cpe:2.3:a:signalwire:sofia-sip:1.11.9
-
cpe:2.3:a:signalwire:sofia-sip:1.12.0
-
cpe:2.3:a:signalwire:sofia-sip:1.12.1
-
cpe:2.3:a:signalwire:sofia-sip:1.12.2
-
cpe:2.3:a:signalwire:sofia-sip:1.12.3
-
cpe:2.3:a:signalwire:sofia-sip:1.12.4
-
cpe:2.3:a:signalwire:sofia-sip:1.13.2
-
cpe:2.3:a:signalwire:sofia-sip:1.13.3
-
cpe:2.3:a:signalwire:sofia-sip:1.13.4
-
cpe:2.3:a:signalwire:sofia-sip:1.13.5
-
cpe:2.3:a:signalwire:sofia-sip:1.13.6
-
cpe:2.3:a:signalwire:sofia-sip:1.13.7
-
cpe:2.3:o:debian:debian_linux:10.0