Security readout for executives and security teams
Plain-English summary
CVE-2022-23547 affects pjproject, a communications library used by applications that handle STUN for NAT traversal. A crafted STUN message can trigger unsafe memory handling, with the main business risk being service disruption and limited information exposure in affected voice, SIP, or multimedia stacks.
Executive priority
Schedule remediation in the normal security patch cycle, accelerated for internet-facing communications services. The risk is meaningful because exploitation could disrupt availability, but current sources do not support emergency handling or confirmed active exploitation.
Technical view
The source describes a heap buffer overflow/CWE-122 and possible buffer overread while parsing certain STUN messages in pjproject versions up to 2.13. The vulnerability is network reachable, requires high attack complexity, needs no authentication or user interaction, and affects applications using STUN, including PJNATH and PJSUA-LIB.
Likely exposure
Exposure is most likely where pjproject <= 2.13 is embedded in applications using STUN, PJNATH, or PJSUA-LIB. Internet-facing or partner-facing real-time communications services deserve priority review, but the bundle does not identify specific downstream products beyond pjproject users.
Exploitation context
The bundle does not show CISA KEV listing or any cited evidence of active exploitation. CVSS indicates network attack surface and no privileges required, but high attack complexity. Treat this as a credible denial-of-service and limited disclosure risk, not confirmed exploitation.
Researcher notes
The record is somewhat imprecise, describing both heap buffer overflow and possible buffer overread. Anchor analysis to the STUN parser issue in pjproject <= 2.13 and the referenced patch commit. Avoid assuming exploitability beyond the published CVSS and affected-component statements.
Mitigation direction
- Upgrade pjproject or apply the vendor patch commit where applicable.
- Use fixed operating-system packages from your distribution when pjproject is packaged.
- Prioritize systems exposing STUN-related functionality to untrusted networks.
- Check vendor guidance for downstream products embedding pjproject.
- Restrict unnecessary external access to affected communications services.
Validation and detection
- Inventory applications and packages using pjproject, PJNATH, or PJSUA-LIB.
- Confirm no deployed pjproject version is <= 2.13 unless patched.
- Verify the vendor patch or distribution security update is present.
- Map whether STUN parsing is reachable from untrusted networks.
- Review service monitoring for crashes around STUN message handling.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-122: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2022-23547 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H2.24.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/pjsip/pjproject/security/advisories/GHSA-cxwq-5g9x-x7frCVE reference · x_refsource_CONFIRM
- https://github.com/pjsip/pjproject/security/advisories/GHSA-9pfh-r8x4-w26wCVE reference · x_refsource_MISC
- https://github.com/pjsip/pjproject/commit/bc4812d31a67d5e2f973fbfaf950d6118226cf36CVE reference · x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2023/08/msg00038.htmlCVE reference
- https://lists.debian.org/debian-lts-announce/2024/09/msg00030.htmlCVE reference
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Heap-based Buffer Overflow
Heap-based Buffer Overflow represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
