PT-2025-39523 · Pexip · Infinity+1

Published

2025-09-26

·

Updated

2025-12-25

·

CVE-2025-59683

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pexip Infinity versions 15.0 through 38.0
Description The Pexip Infinity software contains an issue with Improper Access Control in the Secure Scheduler for Exchange service when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, potentially leading to a denial of service. The issue is actively exploited.
Recommendations Update to Pexip Infinity version 38.1 or later.

Fix

DoS

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-59683

Affected Products

Infinity
Pexip Infinity