{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asippsipp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sipp:sipp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-90778"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SIPp (\u003c= 3.7.7)"],"_cs_severities":["low"],"_cs_tags":["vulnerability","denial-of-service","network-protocol"],"_cs_type":"advisory","_cs_vendors":["SIPp"],"content_html":"\u003cp\u003eSIPp versions 3.7.7 and earlier are vulnerable to a stack-based buffer overflow within the get_peer_tag() function. The vulnerability occurs during the processing of incoming SIP messages when a 'To' header contains a tag parameter exceeding 2048 bytes. An unauthenticated remote attacker can exploit this flaw by sending a specifically crafted SIP message to a listening SIPp instance. Successful exploitation results in the corruption of the stack memory, causing the SIPp process to crash, thereby leading to a denial-of-service condition. Because SIPp is frequently used in telecommunications infrastructure for load testing and stress testing, such a crash can cause significant service disruption in testing environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe primary impact of this vulnerability is a denial-of-service condition where the SIPp service becomes unavailable due to process termination. This vulnerability affects users of SIPp 3.7.7 and earlier across all platforms. Organizations relying on SIPp for network performance validation or protocol testing are at risk of unexpected service outages if exposed to malicious SIP traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all instances of SIPp to a version later than 3.7.7. As the maintainers have not yet provided a fixed release in the source, monitor the official SIPp repository for patch releases addressing CVE-2026-90778. In the interim, implement ingress filtering or deep packet inspection on SIP traffic to identify and drop packets containing 'To' header tag parameters with lengths exceeding 2048 bytes.\u003c/p\u003e\n","date_modified":"2026-09-13T13:25:48Z","date_published":"2026-09-13T13:25:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sipp-buffer-overflow/","summary":"SIPp versions 3.7.7 and earlier contain a buffer overflow vulnerability in the get_peer_tag() function that allows remote attackers to cause a denial of service.","title":"Buffer Overflow Vulnerability in SIPp get_peer_tag()","url":"https://feed.craftedsignal.io/briefs/2026-09-sipp-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:sipp:sipp:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}