Skip to main content
CRITICAL

CVE-2021-43845

CVSS v3

9.1

CRITICAL

EPSS Score

3.7 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users that use PJMEDIA and RTCP XR. A malicious actor can send a RTCP XR message with an invalid packet size.

Technical details

Published
2021-12-27

Frequently asked questions

What is CVE-2021-43845?

PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users that use PJMEDIA and RTCP XR. A malicious actor can send a RTCP XR message with an invalid packet size.

Is CVE-2021-43845 actively exploited?

Active exploitation of CVE-2021-43845 has not been confirmed. Its EPSS score was 3.7% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-43845?

CVE-2021-43845 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2021-43845 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key