Sceawere

Vulnerability Detail

CVE-2026-103104UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pexip Infinity Media DoS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
4h ago
Vendor
Pexip
Product
Infinity
Attack Type
CWE-617 Reachable Assertion
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T03:16:59.467Z",
  "pubdate": "2026-09-30T03:16:59.467Z",
  "executiveSummary": "Pexip Infinity is susceptible to a denial-of-service (DoS) vulnerability originating from improper input validation within its media implementation layer.\nThe vulnerability allows an unauthenticated remote attacker to trigger a software abort by sending specially crafted input to the media processing subsystem.\nAffected versions include Pexip Infinity prior to 38.2, as well as versions 39.0, 39.1, and 40.0.\nSuccessful exploitation results in the abrupt termination of the affected service, leading to a loss of availability for the media processing functionality.\nThe flaw stems from the application's failure to adequately sanitize or validate incoming media data, causing the software to enter an unrecoverable state when presented with malformed packets.\nGiven that the vector is remotely exploitable and requires no specific authentication, the impact on availability is significant for organizations relying on Pexip Infinity for real-time communication services.",
  "technicalDetails": "The vulnerability exists within the media processing implementation of Pexip Infinity. The root cause is identified as improper input validation when handling incoming network media traffic.\nWhen the Pexip Infinity media engine processes packets, it expects specific structures and field values within the data stream. The vulnerability is triggered when an attacker injects a malformed packet designed to violate the internal expectations of the parser.\nBecause the input validation logic is insufficient, the system fails to gracefully handle these anomalous packets. Instead of discarding the malformed data or returning an error code, the parsing function encounters a state it cannot process, triggering a software abort (crash) of the affected process.\nThe attack flow follows a predictable pattern: 1) The attacker initiates a connection or targets an existing media stream handled by the Pexip Infinity infrastructure. 2) The attacker transmits the malformed payload, designed to trigger the specific validation flaw, toward the media port. 3) The media implementation parses the input and encounters the violation. 4) The internal error handling logic initiates a software abort to prevent undefined behavior, resulting in an immediate denial of service for that component.\nThe vulnerability is accessible to remote attackers without requiring prior authentication or elevated privileges. Because the affected component handles external network communication, the attack surface is wide, as it can be reached over standard network protocols utilized by the Pexip media stack.\nThe impact of a successful exploitation is a complete service disruption for the affected media instance. If the crash occurs within a critical process, it may impact multiple active calls or sessions depending on the architecture of the media service. The post-exploitation state is characterized by the cessation of service functionality, requiring manual or automated service restarts to restore normal operations. The vulnerability does not explicitly provide for remote code execution (RCE) based on current analysis, but the forced termination causes immediate, high-impact denial of service."
}
CVE-2026-103104: Pexip Infinity Media DoS Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere