Impact
Pexip Infinity versions before 41.1 contain an improper input validation flaw in the media implementation. The vulnerability can be triggered by a remote attacker sending specially crafted input that causes the software to abort, resulting in a loss of service for all users. This flaw is reflected by CWE-617. The primary consequence is an interruption of communication services, potentially disrupting business operations that rely on Pexip for video conferencing and telepresence.
Affected Systems
The affected line of products is Pexip Infinity. Versions earlier than 41.1 are impacted. No specific patch version is provided in the CNA release notes, so any release equal to or greater than 41.1 should be considered protective.
Risk and Exploitability
The CVSS score of 7.5 indicates a high-severity denial of service vulnerability. While no EPSS score is available and the issue is not currently listed in the CISA KEV catalog, the lack of exploitation data does not diminish the risk of a denial of service event. Attackers can likely trigger the abort by delivering malformed media streams over an open network connection, as the flaw is triggered by remote input. Gaining critical access is not required; any remote party can exploit the flaw if the endpoint is reachable.
OpenCVE Enrichment