CERT Warns of SIP Vulnerabilities | Internet News

CERT Warns of SIP Vulnerabilities

Written By
Ryan Naraine
Ryan Naraine
Feb 21, 2003
1 minute read

The CERT Coordination Center on Thursday warned of numerous security
vulnerabilities in vendor implementations of Session Initiation Protocol
(SIP), a signaling protocol for Web conferencing, telephony, presence,
events notification and instant messaging.

A security
alert
from CERT/CC said the vulnerabilities open the doors for an
attacker to gain unauthorized privileged access, cause denial-of-service
attacks, or cause unstable system behavior.

It warned that text-based SIP protocol, used primarily in
Voice-over IP telephony, instant messaging and other presence applications,
contained holes in the subset related to invite message. Tests on a
variety of popular SIP-enabled products detected “unexpected system behavior
and denial-of-services to remote code execution.”

The Center recommended that SIP-enabled devices and services be disabled
until vendor patches are made available. “As a temporary measure, it may
be possible to limit the scope of these vulnerabilities by blocking access
to SIP devices and services at the network perimeter,” CERT/CC said.

SIP-enabled products from IPTel and Nortel Networks were found to be
vulnerable.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.