Impact
Pexip Infinity prior to version 38.2, as well as releases 39.0, 39.1 and 40.0, contains an improper input validation flaw in the media handling component. The flaw allows a remote attacker to send a crafted media stream that can trigger memory corruption or cause the media engine to abort during processing, resulting in a denial of service. The description does not explicitly state a buffer overflow, but based on the nature of the input validation issue it is inferred that the corruption could arise from a buffer overflow or a similar memory overwrite.
Affected Systems
Pexip Infinity installations running any version before 38.2, and the 39.0, 39.1, and 40.0 releases are affected. All other releases are considered unaffected.
Risk and Exploitability
With a CVSS score of 7.7 this vulnerability is classified as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploit at this time. The likely attack vector is remote via the media interface; a malicious node can push the crafted media stream over an exposed network to trigger the denial of service.
OpenCVE Enrichment