top of page
perceptive_background_267k.jpg

SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server he…

Published:

1 juni 2026 om 22:00:00

Alert date:

2 juni 2026 om 21:03:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Critical Infrastructure

A vulnerability in Verizon IMS SIP signaling stack allows on-path attackers to compromise VoLTE communications due to missing IPsec integrity protection. The vulnerability affects SIP signaling implementation that lacks Security-Client/Security-Server headers and ESP traffic protection. Attackers can perform passive monitoring and active manipulation of unsecured SIP messages across radio and core networks. This compromises confidentiality, integrity, and authenticity of VoLTE signaling traffic. The vulnerability impacts telecommunications infrastructure and voice over LTE services.

Technical details

Mitigation steps:

Affected products:

Verizon IMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page