Sipwise develops a next-generation communication platform serving as a carrier-grade softswitch and VoIP infrastructure component, with disclosed vulnerabilities centered on web-application input-handling and session-management weaknesses including cross-site scripting, cross-site request forgery, and open-redirect flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sipwise over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31584HIGH Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with administrative privileges. | Apr 23, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-28345MEDIUM An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly visit the URL. | Apr 10, 2024 | 5.5 | 19 | NO | NO |
CVE-2021-31583MEDIUM Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via s | Apr 23, 2021 | 5.4 | 19 | NO | NO |
An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL th | Apr 10, 2024 | 3.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sipwise.
Media articles that mention a CVE ID that affects a product developed by Sipwise — matched by CVE ID, not by vendor name.