Authentication Bypass by Spoofing in pjsip - #VU142525

 

Authentication Bypass by Spoofing in pjsip - #VU142525

Published: August 14, 2026


Vulnerability identifier: #VU142525
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to spoof DNS responses and poison the DNS cache.

The vulnerability exists due to improper origin validation and use of insufficiently random values in the asynchronous DNS resolver when processing incoming DNS responses for pending queries. A remote attacker can send a forged DNS response to spoof DNS responses and poison the DNS cache.

A successful attack can poison SIP-related DNS lookups and redirect SIP signaling to an attacker-controlled host.


Affected software

pjsip

Remediation

Install security update from vendor's website.

pjsip - update to 2.18

External References

Related Security Bulletins