Sceawere

Vulnerability Detail

CVE-2026-103102UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pexip Infinity Improper Input Validation

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
4h ago
Vendor
Pexip
Product
Infinity
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-09-30T03:16:59.307Z",
  "pubdate": "2026-09-30T03:16:59.307Z",
  "executiveSummary": "Pexip Infinity versions prior to 41.0 are susceptible to an improper input validation vulnerability within the signaling implementation.\nThis vulnerability allows a remote, unauthenticated attacker to trigger a software abort, resulting in a Denial of Service (DoS) condition.\nThe flaw resides in the processing of signaling data, which, when crafted maliciously, causes the application to terminate unexpectedly.\nExploitation requires the attacker to successfully initiate or interact with a gateway call via a WebRTC or API client.\nThe primary risk is the loss of service availability for the Pexip Infinity infrastructure, potentially disrupting real-time communication sessions across the organization.\nAttackers do not require pre-existing elevated privileges but must have the ability to interact with the target gateway interfaces.",
  "technicalDetails": "The root cause of this vulnerability is improper validation of incoming signaling packets within the Pexip Infinity software stack. Specifically, the signaling implementation fails to correctly sanitize or verify the structure and content of data transmitted through WebRTC or API-based gateway calls.\nWhen a malicious payload is submitted during the signaling phase, the internal state machine or parsing logic encounters an unhandled exception or an invalid state transition. This triggers a critical error in the service, leading to a software abort (crash) of the affected component to ensure system integrity.\nThe attack flow begins with an attacker identifying a reachable Pexip Infinity gateway. The attacker then utilizes a WebRTC client or a scripted API client to establish a signaling handshake. During this interaction, the attacker injects specifically crafted input that deviates from expected signaling protocols. Upon processing this malformed input, the signaling service fails to perform bounds checking or validation, leading to the process abortion.\nAffected components include the signaling modules responsible for handling gateway call setup and teardown. All Pexip Infinity deployments running versions prior to 41.0 are impacted. Because this issue is triggered via network-facing interfaces (WebRTC/API), the attack surface is exposed to any remote user capable of reaching these services.\nPost-exploitation impact is limited to the exhaustion of availability. Once the software abort occurs, the service must typically be manually or automatically restarted, causing a persistent state of downtime if the attacker continues to send the triggering payload. The vulnerability does not appear to facilitate arbitrary code execution or unauthorized data access based on the nature of the software abort, but it provides a significant vector for service disruption and interruption of mission-critical communication workflows."
}
CVE-2026-103102: Pexip Infinity Improper Input Validation (HIGH Severity, CVSS: 8.6) | Sceawere