Port 5061: Session Initiation Protocol over TLS
Port 5061 is the default port for SIP carried over TLS, used in internet telephony and private IP telephone systems to set up and tear down calls. RFC 3261 names 5060 as the default for UDP, TCP and SCTP and 5061 for TLS. IANA registers sips on 5061 for TCP, UDP and SCTP.
Port Details
Security Exposure
A reachable SIP endpoint accepts signaling from anyone who can reach it. Shadowserver notes brute forcing of SIP credentials and call fraud, and separately reports SIP as a UDP amplifier, though that finding concerns 5060/udp rather than the TLS port. Mitel 6800, 6900 and 6900w Series SIP phones appear in the CISA KEV catalog for an argument injection flaw (CVE-2024-41710).
Hardening
- +Restrict 5061 at the firewall to known SIP trunk providers, session border controllers and phone subnets.
- +Require mutual TLS or strong digest credentials for every SIP registration.
- +Disable unencrypted SIP on 5060 where all endpoints support TLS on 5061.
- +Keep PBX, SBC and phone firmware on vendor-supported releases.
Monitoring
Log SIP REGISTER and INVITE failures per source address and alert on bursts of failed registrations or calls to unusual destinations. Watch for TLS handshakes on 5061 from networks outside the provider list.
SIPS Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2024-41710 | Mitel SIP Phones Argument Injection Vulnerability | - | 6.8 | 41.6% | KEV | 2024-08-12 |
Tools for Auditing and Monitoring SIPS
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
What is the difference between port 5060 and 5061?→
RFC 3261 sets 5060 as the default SIP port for UDP, TCP and SCTP and 5061 as the default for SIP over TLS. Port 5061 carries encrypted signaling.
Is port 5061 TCP or UDP?→
SIP over TLS runs on TCP port 5061. IANA also lists sips on UDP and SCTP 5061, but RFC 3261 describes 5061 as the TLS over TCP port.
Which vulnerabilities affect the service on port 5061?→
This database lists 1 CVE related to SIPS, 1 of them confirmed as exploited by CISA. Examples: CVE-2024-41710.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5061 is not guaranteed to be SIPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).