Pexip Infinity
by Pexip
CVEs (52)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10432 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP). | ||
| CVE-2019-7178 | Hig | 0.47 | 7.2 | 0.02 | Sep 25, 2020 | Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup. | ||
| CVE-2019-7177 | Hig | 0.47 | 7.2 | 0.01 | Sep 25, 2020 | Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin. | ||
| CVE-2023-37225 | Med | 0.40 | 6.1 | 0.00 | Dec 25, 2023 | Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links. | ||
| CVE-2017-17477 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views. | ||
| CVE-2025-66378 | Med | 0.38 | 5.9 | 0.00 | Dec 25, 2025 | Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node. | ||
| CVE-2025-49088 | Med | 0.38 | 5.9 | 0.00 | Dec 25, 2025 | Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial… | ||
| CVE-2022-27930 | Med | 0.38 | 5.9 | 0.01 | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed. | ||
| CVE-2020-24615 | Med | 0.35 | 5.3 | 0.01 | Sep 25, 2020 | Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP. | ||
| CVE-2022-25357 | Med | 0.34 | 5.3 | 0.01 | Jul 17, 2022 | Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN. | ||
| CVE-2024-33850 | Med | 0.28 | 4.3 | 0.00 | Jun 10, 2024 | Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting. | ||
| CVE-2014-8779 | 0.00 | — | 0.01 | Feb 3, 2015 | Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys. |
- risk 0.49cvss 7.5epss 0.01
Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
- risk 0.47cvss 7.2epss 0.02
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
- risk 0.47cvss 7.2epss 0.01
Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
- risk 0.40cvss 6.1epss 0.00
Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
- risk 0.40cvss 6.1epss 0.01
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
- risk 0.38cvss 5.9epss 0.00
Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.
- risk 0.38cvss 5.9epss 0.00
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial…
- risk 0.38cvss 5.9epss 0.01
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.
- risk 0.35cvss 5.3epss 0.01
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
- risk 0.34cvss 5.3epss 0.01
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.
- risk 0.28cvss 4.3epss 0.00
Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.
- CVE-2014-8779Feb 3, 2015risk 0.00cvss —epss 0.01
Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.
Page 3 of 3