PT-2026-103016 · Pexip · Pexip Infinity
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pexip Infinity versions prior to 38.2
Pexip Infinity version 39.0
Pexip Infinity version 39.1
Pexip Infinity version 40.0
Description
Improper input validation on Pexip Infinity Conferencing Nodes allows an unauthenticated remote attacker to execute arbitrary code as an unprivileged user.
Recommendations
Update Pexip Infinity versions prior to 38.2 to version 38.2 or later.
Update Pexip Infinity version 39.0 to a patched version.
Update Pexip Infinity version 39.1 to a patched version.
Update Pexip Infinity version 40.0 to a patched version.
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pexip Infinity