top of page
perceptive_background_267k.jpg

SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server he…

Published:

1 June 2026 at 22:00:00

Alert date:

2 June 2026 at 21:03:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Critical Infrastructure

A vulnerability in Verizon IMS SIP signaling stack allows on-path attackers to compromise VoLTE communications due to missing IPsec integrity protection. The vulnerability affects SIP signaling implementation that lacks Security-Client/Security-Server headers and ESP traffic protection. Attackers can perform passive monitoring and active manipulation of unsecured SIP messages across radio and core networks. This compromises confidentiality, integrity, and authenticity of VoLTE signaling traffic. The vulnerability impacts telecommunications infrastructure and voice over LTE services.

Technical details

Mitigation steps:

Affected products:

Verizon IMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page