CVE-2025-49088
Unknown Unknown - Not Provided
Improper Input Validation in Pexip OTJ Causes DoS

Publication date: 2025-12-25

Last updated on: 2025-12-25

Assigner: MITRE

Description
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-25
Last Modified
2025-12-25
Generated
2026-05-07
AI Q&A
2025-12-25
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
pexip infinity 37.1
pexip infinity 32.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Pexip Infinity versions 32.0 through 37.1 before 37.2, specifically in certain configurations of the OTJ (One Touch Join) service for Teams SIP Guest Join. It involves improper input validation in the OTJ service, which allows a remote attacker to send a specially crafted calendar invite that triggers a software abort, causing a denial of service.


How can this vulnerability impact me? :

The vulnerability can lead to a denial of service condition by causing the affected software to abort when processing a maliciously crafted calendar invite. This means that the service could become unavailable or disrupted, impacting users relying on the OTJ feature for Teams SIP Guest Join.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart