Skip to main content

Vendor/product archive

pexip / pexip_infinity CVEs

Beta · best-effort

47 CVEs tagged to pexip / pexip_infinity3 Critical, 36 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2025-66443

Published Dec 25, 2025

Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66379

Published Dec 25, 2025

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66378

Published Dec 25, 2025

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66377

Published Dec 25, 2025

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59683

Published Dec 25, 2025

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allow…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49088

Published Dec 25, 2025

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowin…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48704

Published Dec 25, 2025

Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32096

Published Dec 25, 2025

Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32095

Published Dec 25, 2025

Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-30080

Published Apr 2, 2025

Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37917

Published Apr 2, 2025

Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33850

Published Jun 10, 2024

Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31455

Published Dec 25, 2023

Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31289

Published Dec 25, 2023

Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32263

Published Jul 17, 2022

Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29286

Published Jul 17, 2022

Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27937

Published Jul 17, 2022

Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27936

Published Jul 17, 2022

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27935

Published Jul 17, 2022

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27934

Published Jul 17, 2022

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27933

Published Jul 17, 2022

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27932

Published Jul 17, 2022

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27931

Published Jul 17, 2022

Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27930

Published Jul 17, 2022

Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 47 CVEsPage 1 of 2