Sceawere

Vulnerability Detail

CVE-2026-103099UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pexip Infinity Media DoS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
4h ago
Vendor
Pexip
Product
Infinity
Attack Type
CWE-617 Reachable Assertion
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T03:16:58.717Z",
  "pubdate": "2026-09-30T03:16:58.717Z",
  "executiveSummary": "Pexip Infinity versions prior to 41.1 are susceptible to a denial of service (DoS) vulnerability originating from improper input validation within the system's media processing implementation.\nThe vulnerability allows an unauthenticated remote attacker to trigger an intentional software abort by supplying specifically crafted or malicious input to the media handling subsystem.\nThe primary impact is the immediate termination of the affected media service, leading to a service outage for users relying on that instance.\nThis vulnerability carries a significant risk to availability, as it can be exploited remotely over the network without requiring prior authentication or privileged access to the platform.\nSuccessful exploitation effectively degrades the operational integrity of the Pexip Infinity deployment by forcing the process to crash, thereby denying service to legitimate participants.",
  "technicalDetails": "The root cause of this vulnerability lies in an input validation failure within the Pexip Infinity media implementation layer. The system fails to correctly sanitize or validate incoming data streams before they are processed by internal media handling functions. This lack of rigorous validation creates a memory or state corruption condition when the application encounters unexpected or malformed input sequences.\nWhen a remote attacker transmits specially crafted packets to the target system's media interface, the input validation logic is bypassed or fails to handle the anomalous input correctly. The subsequent processing attempts to operate on this invalid state, triggering a software abort (panic/crash).\nIn terms of attack flow, the attacker initiates a connection to the Pexip Infinity service, typically via a protocol utilized for media transport. By injecting malformed data payloads into this transport stream, the attacker exploits the insecure parsing routine within the media component. Once the payload is ingested, the application's internal integrity checks identify a catastrophic inconsistency in the processed state, leading to a deliberate process termination to prevent further undefined behavior or potential memory corruption exploitation.\nThe affected component is the core media processing engine of Pexip Infinity. Because media streams are inherently exposed to the network to facilitate communication, this component resides on the network edge, making the attack surface significantly large. Exploitation does not require the attacker to have established a legitimate session, nor does it necessitate user privileges, as the vulnerability resides in the pre-authentication or early-phase handling of media packets.\nPost-exploitation impact is limited to the denial of service of the affected service instance. Upon the software abort, the service becomes unresponsive, dropping all active media calls and preventing new connections until the service is manually restarted or monitored by a watchdog process. The vulnerability essentially forces a hard crash, which is an effective method for disrupting real-time communication services."
}
CVE-2026-103099: Pexip Infinity Media DoS Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere