490
VMScore

CVE-2020-28361

Published: 18/11/2020 Updated: 03/12/2020
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Kamailio prior to 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 up to and including 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters. This occurs in the remove_hf function in the Kamailio textops module. Particular use of remove_hf in Sippy Softswitch may allow skilled attacker having a valid credential in the system to disrupt internal call start/duration accounting mechanisms leading potentially to a loss of revenue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kamailio kamailio