CVE-2025-66443

7.5

Pexip · Infinity

Pexip Infinity versions 35.0 to 38.1 contain an improper input validation vulnerability in signalling that can lead to a denial of service via a software abort.

Executive summary

Unauthenticated attackers can trigger a denial of service condition in Pexip Infinity 35.0 through 38.1 by exploiting improper input validation in non-default Direct Media configurations.

Vulnerability

This vulnerability is caused by improper input validation within signalling processes for non-default WebRTC Direct Media configurations. An unauthenticated remote attacker can supply crafted input to trigger a reachable assertion, resulting in a software abort and temporary service interruption.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a high risk due to the ease of exploitation. Successful exploitation results in a denial of service, which can disrupt critical communications and conferencing infrastructure, leading to significant operational downtime for organizations relying on the Pexip platform.

Remediation

Immediate Action: Upgrade to Pexip Infinity version 39.0 or later to resolve the underlying input validation flaw.

Proactive Monitoring: Review system logs for frequent service restarts or unexpected software aborts that may indicate exploitation attempts.

Compensating Controls: If upgrading is not immediately feasible, disable the non-default Direct Media configuration for WebRTC to eliminate the vulnerable attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for service disruption, administrators should prioritize updating to version 39.0 during the next maintenance cycle. Organizations using the Direct Media feature should verify their configuration and apply the patch as soon as possible to ensure platform stability and availability.

More Pexip CVEs

Sources