CVE-2026-10629 PUBLISHED

CVE-2026-10629

Assigner: certcc
Reserved: 02.06.2026 Published: 02.06.2026 Updated: 02.06.2026

SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server headers and ESP traffic), which allows an on-path attacker to compromise confidentiality, integrity, and authenticity of VoLTE signaling via passive monitoring and active manipulation of unsecured SIP messages over the radio and core network.

Product Status

Vendor Verizon
Product VoLTE
Versions
  • Version UNKNOWN is affected

References

Problem Types

  • CWE-346 Origin Validation Error
  • CWE-523 Missing Transport Layer Protection