← Vulnerability feed

Vulnerability record · CVE-2020-27507 · published 15 March 2023

CVE-2020-27507: Kamailio classic buffer overflow vulnerability

Kamailio · Kamailio

The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.

9.8 CVSS 3.1 Critical EPSS 1.2% · top 33.7% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-27507 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-16657Debian linux null pointer dereference vulnerabilityIn Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. T…EPSS 3.6%9.8CVE-2018-14767Debian linux improper input validation vulnerabilityIn Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault an…EPSS 29%9.8CVE-2018-8828Kamailio out-of-bounds write vulnerabilityA Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message wit…EPSS 30%9.8CVE-2013-7426Kamailio unrestricted file upload vulnerabilityInsecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.EPSS 2.2%9.8CVE-2016-2385Debian linux memory buffer overflow vulnerabilityHeap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows r…EPSS 31%7.8CVE-2015-1590Kamailio permissions and access controls vulnerabilityThe kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.EPSS 0.43%7.8CVE-2015-1591Kamailio permissions and access controls vulnerabilityThe kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.EPSS 0.39%7.5CVE-2026-52022Kamailio uncontrolled resource consumption vulnerabilityAn issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling componentsEPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2020-27507), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.