CVE-2020-28361
NixOS vulnerability analysis and mitigation

Overview

Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters. This vulnerability was discovered in the remove_hf function in the Kamailio textops module and was disclosed on November 18, 2020 (NVD).

Technical details

The vulnerability occurs in the remove_hf function within the Kamailio textops module. It allows attackers to bypass header-removal protection mechanisms by exploiting whitespace characters. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.4 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N, and a CVSS v2.0 Base Score of 5.5 (MEDIUM) (NVD).

Impact

The vulnerability primarily affects the integrity of the system, with moderate impact. It can allow skilled attackers with valid credentials to disrupt internal call start/duration accounting mechanisms, potentially leading to revenue loss. The vulnerability enables SIP header injection attacks that could result in toll fraud, caller-id spoofing, and authentication bypass (Sippy Support).

Exploitability

The vulnerability requires a skilled attacker with valid credentials in the system to exploit. Exploit code has been publicly released, as indicated by the presence of a proof-of-concept on security websites (Packet Storm).

Mitigation and workarounds

The primary mitigation is to upgrade to Kamailio version 5.4.0 or later. For Sippy Softswitch users, specific mitigation steps vary by version: users of v5.2 can switch to OpenSIPS, while users of v5.0 and v5.1 should either update to the latest version or upgrade to v5.2 with OpenSIPS enabled. Users of v4.5 and earlier versions should contact Sippy Software support for further instructions (Sippy Support).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management