VYPR

Vendor CVEs

Pexip

All CVEs

56 total · sorted by risk
  • CVE-2022-27930MedJul 17, 2022
    risk 0.38cvss 5.9epss 0.01

    Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.

  • CVE-2020-24615MedSep 25, 2020
    risk 0.35cvss 5.3epss 0.01

    Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.

  • CVE-2023-40236MedDec 25, 2023
    risk 0.34cvss 5.3epss 0.00

    In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypass.

  • CVE-2022-25357MedJul 17, 2022
    risk 0.34cvss 5.3epss 0.01

    Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.

  • CVE-2024-33850MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.

  • CVE-2014-8779Feb 3, 2015
    risk 0.00cvss epss 0.01

    Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.

Page 2 of 2