CVE-2025-66443
Unknown
Unknown - Not Provided
Improper Input Validation in Pexip WebRTC Causes DoS
Publication date: 2025-12-25
Last updated on: 2025-12-25
Assigner: MITRE
Description
Description
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pexip | infinity | 35.0 |
| pexip | infinity | 38.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-617 | The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary. |