Skip to main content

Port Details

Port
5060
Transport
UDP / TCP
Service
SIP
IANA service name
sip
Range
User port (1024-49151)
Related ports

Security Exposure

Shadowserver reports SIP on 5060/udp as a UDP amplifier abused for reflected DDoS, measuring an average amplification factor of 28.4 in 2023. It also notes brute forcing of SIP credentials, access to extensions and subsequent call fraud. SIP on 5060 is not encrypted, so call setup details can be observed on the network path; RFC 3261 defines SIPS over TLS to protect signaling.

Hardening

  • +Restrict 5060/udp to trusted IPs, as Shadowserver recommends, and apply the same limit to 5060/tcp.
  • +Use SIP over TLS on 5061 and SIPS URIs for signaling across untrusted networks.
  • +Enforce strong, unique SIP account passwords and lock out repeated registration failures.

Monitoring

Track failed REGISTER and INVITE authentication attempts per source, and watch for OPTIONS scans or high outbound UDP volumes from 5060.

SIP Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2024-41710
Mitel SIP Phones Argument Injection Vulnerability
-6.841.6%KEV2024-08-12

Tools for Auditing and Monitoring SIP

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is SIP port 5060 TCP or UDP?→

Both. RFC 3261 sets 5060 as the default for UDP, TCP and SCTP. Encrypted SIP over TLS uses 5061.

What is the difference between ports 5060 and 5061?→

Port 5060 carries unencrypted SIP, while 5061 is the default for SIP over TLS according to RFC 3261.

Should port 5060 be open to the internet?→

Only to trusted SIP providers. Shadowserver recommends restricting 5060/udp to trusted IPs because open SIP services are abused for amplification.

Which vulnerabilities affect the service on port 5060?→

This database lists 1 CVE related to SIP, 1 of them confirmed as exploited by CISA. Examples: CVE-2024-41710.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5060 is not guaranteed to be SIP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).