PT-2021-11192 · Pexip · Pexip Infinity

Published

2021-07-07

·

Updated

2021-07-10

·

CVE-2020-25868

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Pexip Infinity versions 22.x through 24.x before 24.2
Description: The issue is related to improper input validation for call setup, allowing an unauthenticated remote attacker to trigger a software abort, resulting in a temporary loss of service.
Recommendations: For versions 22.x through 24.x before 24.2, update to version 24.2 or later to resolve the issue. At the moment, there is no other information about additional mitigation measures for this specific vulnerability.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25868

Affected Products

Pexip Infinity