CVE-2025-32096
7.5Pexip · Infinity
Pexip Infinity versions 33.0 through 37.0 are vulnerable to an improper input validation flaw in signaling, which allows unauthenticated attackers to trigger a software abort and cause a denial of service.
Executive summary
A critical denial of service vulnerability in Pexip Infinity allows unauthenticated attackers to crash affected systems, necessitating an immediate update to version 37.1 or later.
Vulnerability
This vulnerability is classified as a reachable assertion (CWE-617) caused by improper input validation within the signaling component. An unauthenticated attacker can send specially crafted signals to the target system to force a software abort, resulting in a denial of service.
Business impact
The successful exploitation of this vulnerability results in a denial of service, which can cause significant disruption to organizational communications and video conferencing infrastructure. With a CVSS score of 7.5, this flaw represents a high risk to availability, as it requires no user interaction or authentication to trigger. System downtime can impede critical business operations and result in a loss of productivity.
Remediation
Immediate Action: Update Pexip Infinity to version 37.1 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs for repeated signaling errors or unexpected service crashes that may indicate an attempt to trigger the software abort.
Compensating Controls: Ensure that Pexip Infinity deployments are protected by network access controls or firewalls that restrict signaling traffic to authorized sources only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the ease of exploitation and the potential for service disruption, administrators should prioritize the deployment of the vendor provided update. Applying version 37.1 is the only definitive way to resolve the underlying input validation weakness and restore system stability.