
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48704 is an Improper Input Validation vulnerability in Pexip Infinity's signalling component that allows an unauthenticated remote attacker to trigger a software abort, resulting in a denial of service. It affects Pexip Infinity versions 35.0 through 37.2, with version 38.0 serving as the fixed release. The vulnerability was published on December 25, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Pexip Security Bulletins).
The root cause is classified as CWE-617 (Reachable Assertion), meaning the application contains an assertion or abort condition that can be reached through externally controlled input in the signalling interface. An unauthenticated attacker can send specially crafted network traffic to the Pexip Infinity signalling endpoint, causing the software to hit an internal assertion and abort. No authentication, privileges, or user interaction are required, and the attack is conducted entirely over the network with low complexity (Red Hat CVE, Pexip Security Bulletins).
Successful exploitation results in a complete loss of availability for the affected Pexip Infinity service, as the triggered software abort causes the system to become unavailable to users. There is no impact on confidentiality or integrity — the vulnerability is purely a denial-of-service condition. Organizations relying on Pexip Infinity for video conferencing and unified communications infrastructure would experience service outages until the process is restarted or the system is patched (Red Hat CVE).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.04%, indicating a low probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in their weekly vulnerability bulletin for the week of December 22, 2025 (CISA Bulletin, Red Hat CVE).
Pexip has released version 38.0 to address this vulnerability; all users running Pexip Infinity 35.0 through 37.2 should upgrade immediately. As an interim measure where patching is not immediately possible, apply network segmentation to restrict access to the signalling interface to trusted sources only. Monitor for unexpected service interruptions that may indicate exploitation attempts (Pexip Security Bulletins).
The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky shortly after disclosure, with security-focused accounts noting the unauthenticated denial-of-service nature of the flaw. CISA included it in their weekly vulnerability summary bulletin for the week of December 22, 2025. No significant vendor statements beyond the Pexip security bulletin or notable independent researcher commentary have been identified (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."