SignalWire's vulnerability footprint centers on a small set of widely deployed telephony and real-time communications infrastructure products, most notably the Sofia-SIP library and FreeSwitch platform, which sit in the signaling path of VoIP and unified communications systems. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through memory-safety weaknesses including out-of-bounds writes, heap buffer overflows, and integer wraparound conditions that are endemic to C-based protocol parsers and media handlers. Defenders should treat this vendor's advisories as high-priority given the criticality bias of its disclosures and the infrastructure-level role of its products in communications environments; current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Signalwire over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22741CRITICAL Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length | Jan 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-31001HIGH Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cau | May 31, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-31002HIGH Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cau | May 31, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-31003CRITICAL Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access | May 31, 2022 | 9.8 | 25 | NO | NO |
CVE-2021-36513HIGH An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uniniti | Oct 18, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-32307HIGH Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification.
Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/securi | May 26, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Signalwire.
Media articles that mention a CVE ID that affects a product developed by Signalwire — matched by CVE ID, not by vendor name.