CVE-2022-31002 is a high-severity denial-of-service vulnerability affecting Sofia-SIP, an open-source Session Initiation Protocol (SIP) User-Agent library, and related products like FreeSWITCH. An unauthenticated attacker can remotely crash affected systems by sending a specially crafted SIP message containing a malicious URL ending with a '%' character. While the CVSS score is 7.5 (High), there is currently no public exploit code, evidence of active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.8CPE matchmatch criteria | cpe:2.3:a:signalwire:sofia-sip:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.