Impact
Pexip Infinity versions 30.0 through 40.x before 41.0 suffer from improper input validation in the web server, permitting a malicious actor to send crafted requests that render a node inaccessible. The failure of the web server to correctly sanitize input causes a denial‑of‑service condition that interrupts service availability for users and communications relying on that node. The presence of CWE‑770 indicates an out‑of‑memory or resource exhaustion weakness exploited by the attacker to exhaust or corrupt server resources.
Affected Systems
The affected products are Pexip Infinity, specifically all releases from version 30.0 up through any 40.x build prior to 41.0. Users deploying these versions should verify their build number and plan for remediation.
Risk and Exploitability
The CVSS score of 8.6 classifies this as a high‑severity vulnerability. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that while the flaw is serious, it may not yet have widespread exploitation reports. The vulnerability is likely mountable remotely by targeting the Infinity web interface; an attacker must be able to reach the web server over the network and craft the invalid input to trigger the denial of service. Given the absence of additional constraints in the description, the attack vector is inferred to be remote and network‑based.
OpenCVE Enrichment