CVE-2026-10629 Details
Description
SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server headers and ESP traffic), which allows an on-path attacker to compromise confidentiality, integrity, and authenticity of VoLTE signaling via passive monitoring and active manipulation of unsecured SIP messages over the radio and core network.
A vulnerability exists in the SIP signaling stack of Verizon's IMS network, affecting an unspecified version. The issue arises because SIP signaling is implemented without IPsec integrity protection, missing essential Security-Client/Security-Server headers and ESP traffic. This lack of protection allows an on-path attacker to compromise the confidentiality, integrity, and authenticity of VoLTE signaling. Unsecured SIP messages can be passively monitored and actively manipulated over the radio and core network.
Verizon has stated that IPsec integrity support is currently available upon request and will be extended to all user equipment later this year. However, until this network-level enforcement is observed and confirmed, users should assume that VoLTE signaling is untrusted for high-assurance operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 2, 2026CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/615987 | CVE | AdvisoryRemedy |
| https://www.3gpp.org/DynReport/33203.htm | [email protected] | Not Applicable |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Verizon IMS | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | New CVE Received | [email protected] |
| Jun 2, 2026 | CVE Modified | CVE |
Volerion