Vulnerability record · CVE-2021-41145 · published 25 October 2021
CVE-2021-41145: Freeswitch uncontrolled resource consumption vulnerability
Freeswitch · Freeswitch
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Denial of Service via SIP flooding. When flooding FreeSWITCH with SIP messages, it was observed that after a number of seconds the process was killed by the operating system due to memory exhaustion. By abusing this vulnerability, an attacker is able to crash any FreeSWITCH instance by flooding it with SIP messages, leading to Denial of Service. The attack does not require authentication and can be carried out over UDP, TCP or TLS. This issue was patched in version 1.10.7.
Description
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is susceptible to Denial of Service via SIP flooding. When flooding FreeSWITCH with SIP messages, it was observed that after a number of seconds the process was killed by the operating system due to memory exhaustion. By abusing this vulnerability, an attacker is able to crash any FreeSWITCH instance by flooding it with SIP messages, leading to Denial of Service. The attack does not require authentication and can be carried out over UDP, TCP or TLS. This issue was patched in version 1.10.7.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/signalwire/freeswitch/releases/tag/v1.10.7 | Release NotesThird Party Advisory |
| https://github.com/signalwire/freeswitch/security/advisories/GHSA-jvpq-23v4-gp3m | ExploitThird Party Advisory |
| https://github.com/signalwire/freeswitch/releases/tag/v1.10.7 | Release NotesThird Party Advisory |
| https://github.com/signalwire/freeswitch/security/advisories/GHSA-jvpq-23v4-gp3m | ExploitThird Party Advisory |
Track CVE-2021-41145 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41145), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.