Pexip
Pexip Infinity: vulnerabilidades y CVE
Pexip Infinity tiene 57 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE57
Últimos 12 meses19
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-103110 | Crítica (9.8) | 0.61% | — | 30 sept 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node. |
| CVE-2026-103109 | Alta (7.7) | 0.24% | — | 30 sept 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a… |
| CVE-2026-103108 | Alta (7.5) | 0.31% | — | 30 sept 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service |
| CVE-2026-103106 | Alta (7.8) | 0.14% | — | 30 sept 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root.… |
| CVE-2026-103105 | Alta (8.8) | 0.18% | — | 30 sept 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute… |
| CVE-2026-103104 | Alta (7.5) | 0.31% | — | 30 sept 2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. |
| CVE-2026-103102 | Alta (8.6) | 0.32% | — | 30 sept 2026 | Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue… |
| CVE-2026-103101 | Alta (8.6) | 0.27% | — | 30 sept 2026 | Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible. |
| CVE-2026-103100 | Alta (7.5) | 0.26% | — | 30 sept 2026 | Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service. |
| CVE-2026-103099 | Alta (7.5) | 0.31% | — | 30 sept 2026 | Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service. |
| CVE-2025-66443 | Media (5.3) | 0.31% | — | 25 dic 2025 | Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in… |
| CVE-2025-66379 | Alta (7.5) | 0.37% | — | 25 dic 2025 | Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service. |
| CVE-2025-66378 | Alta (7.5) | 0.25% | — | 25 dic 2025 | Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy Node. |
| CVE-2025-66377 | Alta (7.5) | 0.21% | — | 25 dic 2025 | Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to… |
| CVE-2025-59683 | Crítica (9.1) | 0.33% | — | 25 dic 2025 | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially… |
| CVE-2025-49088 | Media (5.9) | 0.32% | — | 25 dic 2025 | Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a… |
| CVE-2025-48704 | Alta (7.5) | 0.31% | — | 25 dic 2025 | Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service. |
| CVE-2025-32096 | Alta (7.5) | 0.31% | — | 25 dic 2025 | Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service. |
| CVE-2025-32095 | Alta (7.5) | 0.42% | — | 25 dic 2025 | Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service. |
| CVE-2025-30080 | Alta (7.5) | 0.52% | — | 2 abr 2025 | Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to trigger a temporary denial of service (software abort). |
| CVE-2024-37917 | Alta (7.5) | 0.49% | — | 2 abr 2025 | Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message. |
| CVE-2024-33850 | Media (4.3) | 0.21% | — | 10 jun 2024 | Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the… |
| CVE-2023-37225 | Media (6.1) | 0.31% | — | 25 dic 2023 | Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links. |
| CVE-2023-31455 | Alta (7.5) | 0.61% | — | 25 dic 2023 | Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort. |
| CVE-2023-31289 | Alta (7.5) | 0.61% | — | 25 dic 2023 | Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort. |
| CVE-2022-32263 | Alta (7.5) | 1.0% | — | 17 jul 2022 | Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719. |
| CVE-2022-29286 | Alta (7.5) | 1.1% | — | 17 jul 2022 | Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishandling. |
| CVE-2022-27937 | Alta (7.5) | 1.1% | — | 17 jul 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. |
| CVE-2022-27936 | Alta (7.5) | 1.1% | — | 17 jul 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323. |
| CVE-2022-27935 | Alta (7.5) | 1.1% | — | 17 jul 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.