Infinity
by Pexip
CVEs (62)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42555 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation. | ||
| CVE-2021-35969 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation. | ||
| CVE-2021-33499 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2). | ||
| CVE-2021-33498 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2). | ||
| CVE-2021-32545 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation. | ||
| CVE-2021-31925 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2021 | Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface. | ||
| CVE-2020-25868 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2021 | Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service). | ||
| CVE-2020-13387 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323. | ||
| CVE-2020-12824 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP. | ||
| CVE-2018-10585 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | Pexip Infinity before 18 allows remote Denial of Service (XML parsing). | ||
| CVE-2018-10432 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP). | ||
| CVE-2019-7178 | Hig | 0.47 | 7.2 | 0.02 | Sep 25, 2020 | Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup. | ||
| CVE-2019-7177 | Hig | 0.47 | 7.2 | 0.01 | Sep 25, 2020 | Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin. | ||
| CVE-2023-37225 | Med | 0.40 | 6.1 | 0.00 | Dec 25, 2023 | Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links. | ||
| CVE-2017-17477 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views. | ||
| CVE-2025-66378 | Med | 0.38 | 5.9 | 0.00 | Dec 25, 2025 | Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node. | ||
| CVE-2025-49088 | Med | 0.38 | 5.9 | 0.00 | Dec 25, 2025 | Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial… | ||
| CVE-2022-27930 | Med | 0.38 | 5.9 | 0.01 | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed. | ||
| CVE-2020-24615 | Med | 0.35 | 5.3 | 0.01 | Sep 25, 2020 | Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP. | ||
| CVE-2022-25357 | Med | 0.34 | 5.3 | 0.01 | Jul 17, 2022 | Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN. |
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a denial of service via the administrative web interface.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
- risk 0.47cvss 7.2epss 0.02
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
- risk 0.47cvss 7.2epss 0.01
Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
- risk 0.40cvss 6.1epss 0.00
Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
- risk 0.40cvss 6.1epss 0.01
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
- risk 0.38cvss 5.9epss 0.00
Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.
- risk 0.38cvss 5.9epss 0.00
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial…
- risk 0.38cvss 5.9epss 0.01
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.
- risk 0.35cvss 5.3epss 0.01
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
- risk 0.34cvss 5.3epss 0.01
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.
Page 3 of 4