#VU69269 Cleartext transmission of sensitive information in pjsip - CVE-2022-39269
Published: November 14, 2022 / Updated: November 24, 2022
pjsip
pjsip
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent insecurely. A remote attacker with ability to intercept network traffic can gain access to sensitive data.