CVE-2025-32095
7.5Pexip · Infinity
Pexip Infinity versions prior to 37.0 are vulnerable to a remote denial of service attack caused by improper input validation in the signalling process.
Executive summary
Pexip Infinity versions before 37.0 contain a critical input validation flaw that allows remote, unauthenticated attackers to cause a service outage via a crafted signalling message.
Vulnerability
This vulnerability involves improper input validation (CWE-617) within the signalling component, which enables an unauthenticated remote attacker to trigger a software abort and subsequent denial of service.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting its high impact on system availability. Successful exploitation allows an attacker to disrupt critical communication services provided by the platform, potentially leading to significant operational downtime and loss of service accessibility for end users.
Remediation
Immediate Action: Organizations must update Pexip Infinity to version 37.0 or later immediately to resolve the vulnerable signalling component.
Proactive Monitoring: Security teams should monitor system logs for frequent or unexpected service restarts and abnormal signalling patterns that may indicate an attempt to trigger a software abort.
Compensating Controls: Deploy network-level ingress filtering to restrict access to the signalling ports of the Pexip Infinity deployment to known, trusted IP ranges where possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high impact on service availability and the ease with which an unauthenticated attacker can trigger a denial of service, administrators are urged to prioritize the update to version 37.0. Testing and deploying this patch is essential to maintain the stability and reliability of the Pexip Infinity environment against potential service-disruption attacks.