CVE-2025-66377
7.5Pexip · Infinity
A missing authentication flaw in a Pexip Infinity internal API allows an attacker with existing node access to compromise the integrity and availability of other nodes in the installation.
Executive summary
An authentication vulnerability in Pexip Infinity versions prior to 39.0 permits an attacker with local node access to escalate their impact across the entire product installation.
Vulnerability
This vulnerability involves missing authentication for a critical function within a product-internal API (CWE-306). An attacker who has already achieved code execution on one node can leverage this flaw to interact with and impact the operation of other nodes within the same Pexip Infinity cluster.
Business impact
The ability to move laterally or impact operations across an entire Pexip Infinity installation poses a significant risk to organizational communications and service availability. With a CVSS score of 7.5, this high-severity flaw could lead to unauthorized control over the conferencing infrastructure, potentially resulting in complete service disruption or unauthorized interception of sensitive communication data.
Remediation
Immediate Action: Upgrade all Pexip Infinity nodes to version 39.0 or later to ensure the authentication requirements are properly enforced across the internal API.
Proactive Monitoring: Review internal system logs for unauthorized API calls between nodes and monitor for anomalous traffic patterns originating from internal nodes that are not performing standard administrative tasks.
Compensating Controls: Ensure that network segmentation is strictly enforced between nodes and restrict access to the internal API interfaces to authorized management segments only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for cluster-wide impact and the high CVSS severity, administrators should prioritize the upgrade to version 39.0 immediately. Preventing lateral movement within the Pexip environment is essential to maintaining the confidentiality and reliability of enterprise communication services.