Skip to main content

Port Details

Port
5061
Transport
TCP
Service
SIPS
IANA service name
sips
Range
User port (1024-49151)
Related ports

Security Exposure

A reachable SIP endpoint accepts signaling from anyone who can reach it. Shadowserver notes brute forcing of SIP credentials and call fraud, and separately reports SIP as a UDP amplifier, though that finding concerns 5060/udp rather than the TLS port. Mitel 6800, 6900 and 6900w Series SIP phones appear in the CISA KEV catalog for an argument injection flaw (CVE-2024-41710).

Hardening

  • +Restrict 5061 at the firewall to known SIP trunk providers, session border controllers and phone subnets.
  • +Require mutual TLS or strong digest credentials for every SIP registration.
  • +Disable unencrypted SIP on 5060 where all endpoints support TLS on 5061.
  • +Keep PBX, SBC and phone firmware on vendor-supported releases.

Monitoring

Log SIP REGISTER and INVITE failures per source address and alert on bursts of failed registrations or calls to unusual destinations. Watch for TLS handshakes on 5061 from networks outside the provider list.

SIPS Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2024-41710
Mitel SIP Phones Argument Injection Vulnerability
-6.841.6%KEV2024-08-12

Tools for Auditing and Monitoring SIPS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Frequently Asked Questions

What is the difference between port 5060 and 5061?→

RFC 3261 sets 5060 as the default SIP port for UDP, TCP and SCTP and 5061 as the default for SIP over TLS. Port 5061 carries encrypted signaling.

Is port 5061 TCP or UDP?→

SIP over TLS runs on TCP port 5061. IANA also lists sips on UDP and SCTP 5061, but RFC 3261 describes 5061 as the TLS over TCP port.

Which vulnerabilities affect the service on port 5061?→

This database lists 1 CVE related to SIPS, 1 of them confirmed as exploited by CISA. Examples: CVE-2024-41710.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5061 is not guaranteed to be SIPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).