CVE-2025-48704: 
Pexip Infinity Management Node vulnerability analysis and mitigation

Overview

CVE-2025-48704 is an Improper Input Validation vulnerability in Pexip Infinity's signalling component that allows an unauthenticated remote attacker to trigger a software abort, resulting in a denial of service. It affects Pexip Infinity versions 35.0 through 37.2, with version 38.0 serving as the fixed release. The vulnerability was published on December 25, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Pexip Security Bulletins).

Technical details

The root cause is classified as CWE-617 (Reachable Assertion), meaning the application contains an assertion or abort condition that can be reached through externally controlled input in the signalling interface. An unauthenticated attacker can send specially crafted network traffic to the Pexip Infinity signalling endpoint, causing the software to hit an internal assertion and abort. No authentication, privileges, or user interaction are required, and the attack is conducted entirely over the network with low complexity (Red Hat CVE, Pexip Security Bulletins).

Impact

Successful exploitation results in a complete loss of availability for the affected Pexip Infinity service, as the triggered software abort causes the system to become unavailable to users. There is no impact on confidentiality or integrity — the vulnerability is purely a denial-of-service condition. Organizations relying on Pexip Infinity for video conferencing and unified communications infrastructure would experience service outages until the process is restarted or the system is patched (Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.04%, indicating a low probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in their weekly vulnerability bulletin for the week of December 22, 2025 (CISA Bulletin, Red Hat CVE).

Indicators of compromise

  • Network: Unexpected or malformed signalling traffic directed at Pexip Infinity endpoints from unknown or untrusted sources.
  • Logs: Sudden software abort or crash entries in Pexip Infinity system logs, particularly in the signalling component, without a clear operational cause.
  • Process: Unexpected termination or restart of Pexip Infinity services, especially if correlated with inbound network activity from external sources.

Mitigation and workarounds

Pexip has released version 38.0 to address this vulnerability; all users running Pexip Infinity 35.0 through 37.2 should upgrade immediately. As an interim measure where patching is not immediately possible, apply network segmentation to restrict access to the signalling interface to trusted sources only. Monitor for unexpected service interruptions that may indicate exploitation attempts (Pexip Security Bulletins).

Community reactions

The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky shortly after disclosure, with security-focused accounts noting the unauthenticated denial-of-service nature of the flaw. CISA included it in their weekly vulnerability summary bulletin for the week of December 22, 2025. No significant vendor statements beyond the Pexip security bulletin or notable independent researcher commentary have been identified (CISA Bulletin).

Additional resources


Source: This report was generated using AI

Related Pexip Infinity Management Node vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103110CRITICAL9.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103109CRITICAL9.4
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103105HIGH8.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103106HIGH7.8
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026
CVE-2026-103108HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management