CVE-2022-39244 is a critical buffer overflow vulnerability affecting PJSIP versions prior to 2.13, impacting its parser, RTP decoder, and SDP parser. With a CVSS score of 9.8, it allows unauthenticated remote attackers to achieve high confidentiality, integrity, and availability impacts with low attack complexity. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation. Users are strongly advised to upgrade to PJSIP 2.13 or later as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.13CPE matchmatch criteria | cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.