Port 5060: Session Initiation Protocol
SIP sets up, modifies and ends voice, video and messaging sessions. RFC 3261 makes 5060 the default port for SIP over UDP, TCP and SCTP and 5061 the default for SIP over TLS. Shadowserver describes SIP use in internet telephony, private IP telephone systems and VoLTE.
Port Details
Security Exposure
Shadowserver reports SIP on 5060/udp as a UDP amplifier abused for reflected DDoS, measuring an average amplification factor of 28.4 in 2023. It also notes brute forcing of SIP credentials, access to extensions and subsequent call fraud. SIP on 5060 is not encrypted, so call setup details can be observed on the network path; RFC 3261 defines SIPS over TLS to protect signaling.
Hardening
- +Restrict 5060/udp to trusted IPs, as Shadowserver recommends, and apply the same limit to 5060/tcp.
- +Use SIP over TLS on 5061 and SIPS URIs for signaling across untrusted networks.
- +Enforce strong, unique SIP account passwords and lock out repeated registration failures.
Monitoring
Track failed REGISTER and INVITE authentication attempts per source, and watch for OPTIONS scans or high outbound UDP volumes from 5060.
SIP Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2024-41710 | Mitel SIP Phones Argument Injection Vulnerability | - | 6.8 | 41.6% | KEV | 2024-08-12 |
Tools for Auditing and Monitoring SIP
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is SIP port 5060 TCP or UDP?→
Both. RFC 3261 sets 5060 as the default for UDP, TCP and SCTP. Encrypted SIP over TLS uses 5061.
What is the difference between ports 5060 and 5061?→
Port 5060 carries unencrypted SIP, while 5061 is the default for SIP over TLS according to RFC 3261.
Should port 5060 be open to the internet?→
Only to trusted SIP providers. Shadowserver recommends restricting 5060/udp to trusted IPs because open SIP services are abused for amplification.
Which vulnerabilities affect the service on port 5060?→
This database lists 1 CVE related to SIP, 1 of them confirmed as exploited by CISA. Examples: CVE-2024-41710.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5060 is not guaranteed to be SIP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).