Pexip Infinity
by Pexip
CVEs (52)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11805 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2020 | Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN. | ||
| CVE-2015-4719 | Cri | 0.64 | 9.8 | 0.01 | Sep 24, 2020 | The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request. | ||
| CVE-2017-6551 | Cri | 0.64 | 9.8 | 0.04 | May 2, 2017 | Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes. | ||
| CVE-2025-59683 | Hig | 0.53 | 8.2 | 0.00 | Dec 25, 2025 | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to… | ||
| CVE-2022-27933 | Hig | 0.53 | 8.2 | 0.01 | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. | ||
| CVE-2022-26656 | Hig | 0.53 | 8.2 | 0.01 | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join. | ||
| CVE-2025-66443 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2025 | Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service. | ||
| CVE-2025-66379 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2025 | Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service. | ||
| CVE-2025-66377 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2025 | Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation. | ||
| CVE-2025-48704 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2025 | Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service. | ||
| CVE-2025-32096 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2025 | Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service. | ||
| CVE-2025-32095 | Hig | 0.49 | 7.5 | 0.00 | Dec 25, 2025 | Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service. | ||
| CVE-2025-30080 | Hig | 0.49 | 7.5 | 0.01 | Apr 2, 2025 | Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort). | ||
| CVE-2024-37917 | Hig | 0.49 | 7.5 | 0.00 | Apr 2, 2025 | Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message. | ||
| CVE-2023-31455 | Hig | 0.49 | 7.5 | 0.01 | Dec 25, 2023 | Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort. | ||
| CVE-2023-31289 | Hig | 0.49 | 7.5 | 0.01 | Dec 25, 2023 | Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort. | ||
| CVE-2022-32263 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2022 | Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719. | ||
| CVE-2022-29286 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2022 | Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling. | ||
| CVE-2022-27937 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. | ||
| CVE-2022-27936 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323. |
- risk 0.64cvss 9.8epss 0.01
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
- risk 0.64cvss 9.8epss 0.01
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
- risk 0.64cvss 9.8epss 0.04
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.
- risk 0.53cvss 8.2epss 0.00
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to…
- risk 0.53cvss 8.2epss 0.01
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
- risk 0.53cvss 8.2epss 0.01
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.01
Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).
- risk 0.49cvss 7.5epss 0.00
Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.
Page 1 of 3