Impact
Pexip Infinity versions prior to 40.1 are affected by an improper input validation flaw in the signaling implementation. An attacker can send malformed signaling data, causing the application to abort and terminate processing. This abort results in a denial of service where the instance stops handling calls and may require a restart, impacting availability while leaving confidentiality and integrity unaffected.
Affected Systems
All installations of Pexip Infinity running any version earlier than 40.1 are vulnerable. No other Pexip products or later versions are known to be affected.
Risk and Exploitability
The CVSS score of 7.5 reflects a moderate to high risk primarily due to the service availability impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying limited evidence of active exploitation. Based on the description, it is inferred that an attacker can send malformed signaling data over the network to trigger the abort. The likely attack vector is inferred to involve network access to the signaling interface; a remote actor who can transmit crafted packets may cause the service to terminate without needing credentials.
OpenCVE Enrichment