PT-2026-45769 · Verizon · Verizon Ims

·

CVE-2026-10629

·

Published

2026-06-02

·

Updated

2026-06-08

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Verizon IMS (affected versions not specified)
Description The SIP signaling stack implements SIP signaling without IPsec integrity protection, specifically lacking Security-Client/Security-Server headers and ESP traffic. This allows an on-path attacker to compromise the confidentiality, integrity, and authenticity of VoLTE signaling through passive monitoring and active manipulation of unsecured SIP messages over the radio and core network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10629

Affected Products

Verizon Ims