Pexip
56 known vulnerabilities
Top Products
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improp
Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trig
Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacke
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an att
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, w
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join
Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trig
Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigg
Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a softwa
Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to t
Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so
Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, whic
Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.
Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.
Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.
Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because
Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Unive
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP.
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via On
Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a softw
Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP.
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if
Pexip Infinity before 27.0 has improper WebRTC input validation. An unauthenticated remote attacker can use excessive re
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validat
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validatio
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
Pexip Infinity 25.x before 25.4 has Improper Input Validation, and thus an unauthenticated remote attacker can cause a d
Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote att
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.
Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
Frequently Asked Questions
How many CVEs affect Pexip?
Pexip has 56 CVE records in our database, including 6 critical and 41 high severity vulnerabilities.
What are the most severe Pexip vulnerabilities?
Pexip has 6 critical severity (CVSS 9.0+) and 41 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Pexip vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Pexip products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Pexip Vulnerabilities
CyberStrike scans your infrastructure for Pexip vulnerabilities and provides real-time remediation guidance.
Get Started