CVE-2025-48704

7.5

Pexip · Infinity

Pexip Infinity versions 35.0 through 37.2 contain an improper input validation flaw in signalling that allows unauthenticated attackers to trigger a software abort, resulting in a denial of service.

Executive summary

A critical denial of service vulnerability in Pexip Infinity allows unauthenticated remote attackers to crash the software by triggering a reachable assertion.

Vulnerability

The vulnerability stems from improper input validation within the signalling component, categorized as a reachable assertion (CWE-617). This flaw permits an unauthenticated attacker to remotely induce a software abort, effectively rendering the service unavailable.

Business impact

The exploitation of this vulnerability leads to a denial of service, which directly impacts the availability of critical communication infrastructure. Given the CVSS score of 7.5, this high severity rating reflects the ease of exploitation, as it requires no authentication and can be triggered remotely. Organizations relying on Pexip for real time collaboration may face significant operational downtime and service disruption if this flaw is targeted.

Remediation

Immediate Action: Upgrade Pexip Infinity to version 38.0 or higher immediately to resolve the input validation vulnerability.

Proactive Monitoring: Monitor system logs for repeated connection attempts or abnormal signalling patterns that may indicate a deliberate attempt to trigger the software abort.

Compensating Controls: While a patch is the only definitive fix, ensure that perimeter firewalls restrict access to signalling ports to known, trusted endpoints to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk to service availability and should be treated with urgency. Administrators must prioritize the deployment of Pexip Infinity 38.0 across all affected instances to eliminate the risk of remote denial of service attacks. Failure to patch leaves the signalling infrastructure exposed to simple, unauthenticated disruption attempts.

More Pexip CVEs

Sources