In FreeSWITCH versions prior to 1.10.7, SIP MESSAGE requests (RFC 3428) are not authenticated by default. This allows any unauthenticated remote party to send SIP MESSAGE requests to any SIP user agent registered with the FreeSWITCH server. The vulnerability arises because the 'auth-messages' parameter is set to false by default, resulting in the server relaying unauthenticated MESSAGE requests to clients. This can be abused for message spoofing and spam.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains 'PewSWITCH', a Go-based toolkit for scanning and exploiting two FreeSWITCH SIP server vulnerabilities: CVE-2021-37624 and CVE-2021-41157. The tool allows users to specify target SIP servers and extensions, and can send crafted SIP MESSAGE and SUBSCRIBE packets to test for and exploit these vulnerabilities. The main entry point is 'main.go', which parses command-line arguments and orchestrates scanning and exploitation. The codebase includes modules for each CVE, utility functions for network operations, and supports output in both JSON and CSV formats. Sample configuration and output files are provided. The exploit demonstrates operational capability by allowing custom message content and event subscriptions, confirming vulnerabilities through observable network behavior. The attack vector is network-based, targeting SIP (UDP, typically port 5060) endpoints. The tool is not part of a larger framework and is self-contained.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.