#VU69269 Cleartext transmission of sensitive information in pjsip


Published: 2022-11-14 | Updated: 2022-11-24

Vulnerability identifier: #VU69269

Vulnerability risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-39269

CWE-ID: CWE-319

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
pjsip
Universal components / Libraries / Libraries used by multiple products

Vendor: pjsip

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent insecurely. A remote attacker with ability to intercept network traffic can gain access to sensitive data.

Mitigation
Install update from vendor's website.

Vulnerable software versions

pjsip: 2.11 - 2.12.1


External links
http://github.com/pjsip/pjproject/commit/d2acb9af4e27b5ba75d658690406cec9c274c5cc
http://github.com/pjsip/pjproject/security/advisories/GHSA-wx5m-cj97-4wwg


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability