Impact
Pexip Infinity contains an improper input validation flaw in its media implementation that allows a remote attacker to trigger a software abort, resulting in a denial of service. The vulnerability is rooted in the handling of media stream data, where unexpected or malformed input can compel the system to terminate processes without graceful recovery, disrupting communication services for users.
Affected Systems
Versions of Pexip Infinity older than 38.2, as well as the 39.0, 39.1 and 40.0 releases, are vulnerable. All deployments of these releases are at risk unless updated to a patched version released after these milestones.
Risk and Exploitability
The flaw scores a CVSS base of 7.5, indicating high severity, and it is exploitable from the network via remote input to the media component. Although a specific EPSS score is not available, the lack of a CISA KEV listing does not negate the urgency; the remote nature of the exploit coupled with the ability to bring the system down makes this a significant threat. An attacker can initiate a denial-of-service by sending crafted media packets, potentially overwhelming or crashing the service and denying business continuity for users.
OpenCVE Enrichment