Sceawere

Vulnerability Detail

CVE-2026-103108UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pexip Infinity Media Denial-of-Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
4h ago
Vendor
Pexip
Product
Infinity
Attack Type
CWE-617 Reachable Assertion
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T03:16:59.920Z",
  "pubdate": "2026-09-30T03:16:59.920Z",
  "executiveSummary": "Pexip Infinity is susceptible to a denial-of-service (DoS) vulnerability originating from improper input validation within its media processing subsystem.\nThe vulnerability allows an unauthenticated remote attacker to trigger an unrecoverable software abort by supplying malformed or specifically crafted input data to the affected media implementation.\nSuccessful exploitation results in the abrupt termination of the media service, rendering the Pexip Infinity instance unavailable for communication or processing tasks until manual intervention or service recovery occurs.\nThe risk is categorized as critical for availability, as it allows for service disruption without requiring prior authentication or elevated privileges.\nAffected software versions include Pexip Infinity before 38.2, 39.0, 39.1, and 40.0.\nOrganizations are advised to upgrade to patched versions as soon as possible to mitigate the potential for service degradation.",
  "technicalDetails": "The vulnerability resides within the media implementation component of Pexip Infinity, where incoming media stream inputs fail to undergo sufficient validation before being processed by the underlying software stack.\nThe root cause is identified as an input validation flaw that results in an unhandled exception or critical state error when the media processor encounters unexpected, malformed, or malicious data structures.\nWhen the input validator fails to sanitize or verify the integrity of the incoming data, it leads to a violation of memory safety constraints or a logical failure in the processing pipeline, forcing the application to initiate a software abort.\nThe attack flow involves a remote attacker transmitting a crafted payload targeting the media processing interface. Because the vulnerability exists at a low level in the media handling logic, the attacker does not require authenticated access to the system to initiate the sequence.\nOnce the malformed input is received, the media subsystem attempts to parse or process the data. Due to the lack of adequate bounds checking or format verification, the input triggers a runtime error that the application cannot handle internally.\nThis resulting software abort leads to the immediate cessation of media processing threads or the entire process, effectively denying service to legitimate users attempting to utilize the platform for conferencing or communication services.\nThe impact is persistent until the affected services are restarted. Because the attack vector is network-based and does not necessitate privileged access, the service is vulnerable to automated exploitation or targeted disruption by any entity capable of reaching the Pexip Infinity media interfaces.\nThis behavior represents a failure in defensive programming within the media stack, where the software assumes trust in the structure of incoming packets rather than implementing robust validation protocols to protect against malformed stream headers or payload data."
}
CVE-2026-103108: Pexip Infinity Media Denial-of-Service (HIGH Severity, CVSS: 7.5) | Sceawere