In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic of the media-relay core allows remote attackers to inject or intercept RTP/SRTP media streams via RTP packets (except when the relay is configured for strict source and learning disabled). Version 13.4.1.1 fixes the heuristic mode by limiting exposure to the first five packets, and introduces a recrypt flag that fully prevents SRTP attacks when both mitigations are enabled.
Conclusion & alert: CVE-2025-53399 is rated Moderate Risk (54/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.78%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-28 | 0.27% | 0.78% | +0.51% |
| 2 | 2026-04-17 | 0.19% | 0.27% | +0.08% |
| 3 | 2026-01-09 | — | 0.19% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.9 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2025-53399: 1 source package rows (rtpengine); 6 state rows across 3 repos (3.22-community, 3.23-community, edge-community); fixed 0, open 6. | https://security.alpinelinux.org/vuln/CVE-2025-53399 |
debian
|
not yet assigned | CVE-2025-53399 not yet assigned priority: Debian including 1 source packages (rtpengine), 4 status rows across 4 suites (bookworm, forky, sid, trixie): open 2, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2025-53399 |
ubuntu
|
medium | CVE-2025-53399 medium priority: Ubuntu including 1 source packages (rtpengine), 5 status rows across 5 suites (jammy, noble, plucky, questing, upstream): needs-triage 3, DNE 1, ignored 1. | https://ubuntu.com/security/CVE-2025-53399 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||