VYPR

Pexip Infinity

by Pexip

CVEs (52)

  • CVE-2018-10432HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).

  • CVE-2019-7178HigSep 25, 2020
    risk 0.47cvss 7.2epss 0.02

    Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.

  • CVE-2019-7177HigSep 25, 2020
    risk 0.47cvss 7.2epss 0.01

    Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.

  • CVE-2023-37225MedDec 25, 2023
    risk 0.40cvss 6.1epss 0.00

    Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.

  • CVE-2017-17477MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.

  • CVE-2025-66378MedDec 25, 2025
    risk 0.38cvss 5.9epss 0.00

    Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

  • CVE-2025-49088MedDec 25, 2025
    risk 0.38cvss 5.9epss 0.00

    Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial…

  • CVE-2022-27930MedJul 17, 2022
    risk 0.38cvss 5.9epss 0.01

    Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.

  • CVE-2020-24615MedSep 25, 2020
    risk 0.35cvss 5.3epss 0.01

    Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.

  • CVE-2022-25357MedJul 17, 2022
    risk 0.34cvss 5.3epss 0.01

    Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.

  • CVE-2024-33850MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.

  • CVE-2014-8779Feb 3, 2015
    risk 0.00cvss epss 0.01

    Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.

Page 3 of 3