CVE-2022-39269

    Dashboard / Vulnerabilities / CVE-2022-39269

    CVE-2022-39269

    Published: 6 Oct 2022Last Modified: 12 Aug 2026

    Summary: Media transport downgrade from the secure version (SRTP) to non-secure (RTP) in pjsip

    Details: PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent insecurely. The vulnerability impacts all PJSIP users that use SRTP. The patch is available as commit d2acb9a in the master branch of the project and will be included in version 2.13. Users are advised to manually patch or to upgrade. There are no known workarounds for this vulnerability.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 842b4ba27d8540a11823d5207a452153412a57d2

    Affected versions

    2.12

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-39269 | CVE-DB