Impact
Improper input validation in Pexip Infinity's media implementation allows a remote attacker to cause a software abort, resulting in a denial of service. The CWE-617 vulnerability indicates that untrusted input is used without proper filtering, leading to application failure. This flaw can disable VoIP, video, or other media services that rely on the affected components, potentially disrupting communications for all users on the system.
Affected Systems
All Pexip Infinity deployments running versions before 38.2, as well as the 39.0, 39.1, and 40.0 releases, are affected. Versions 38.2 and later that are not 39.0, 39.1, or 40.0 are presumed not to contain the issue, but the latest stable release should always be verified.
Risk and Exploitability
The CVSS score of 7.5 classifies this vulnerability as high severity. No EPSS score is available, so the exact likelihood of exploitation is unclear, but the fact that it is not listed in the CISA KEV catalog suggests that there are currently no publicly known exploits. The attack vector is remote, targeting the media implementation over the network. An attacker could trigger the abort by sending a crafted request from outside the network or from a compromised internal host, causing a denial of service that affects all users of the system.
OpenCVE Enrichment