CVE-2025-66443
Pexip Infinity Management Node vulnerability analysis and mitigation

Overview

CVE-2025-66443 is an Improper Input Validation vulnerability in Pexip Infinity affecting versions 35.0 through 38.1 (before 39.0) that allows a remote, unauthenticated attacker to trigger a software abort, resulting in a temporary denial of service. The vulnerability is limited to non-default configurations that use Direct Media for WebRTC. It was published on December 25, 2025, with a patch released in version 39.0. The CVSS v3.1 base score is 5.3 (Medium) per NVD, though ENISA's EUVD rates it 7.5 (High) based on a higher availability impact assessment (Red Hat CVE, Pexip Security Bulletins).

Technical details

The root cause is classified as CWE-617 (Reachable Assertion) — a condition where a reachable assertion in the signalling code can be triggered by malformed or unexpected input, causing the process to abort. An attacker sends specially crafted signalling messages over the network targeting Pexip Infinity instances configured to use Direct Media for WebRTC; no authentication or user interaction is required. The vulnerability exists only in non-default configurations, meaning standard deployments without Direct Media for WebRTC are not affected. No public proof-of-concept code has been identified (Red Hat CVE, Pexip Security Bulletins).

Impact

Successful exploitation causes a software abort in the affected Pexip Infinity service, resulting in a temporary denial of service that renders the conferencing platform unavailable until the service is restarted. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. The scope is restricted to organizations running Pexip Infinity versions 35.0–38.1 with Direct Media for WebRTC enabled, a non-default configuration (Red Hat CVE).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of reporting. The EPSS score is approximately 0.04%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack requires no authentication and no user interaction, but is constrained to a specific non-default configuration, limiting the exposed attack surface (Red Hat CVE, Pexip Security Bulletins).

Indicators of compromise

  • Logs: Unexpected software abort or crash events in Pexip Infinity service logs; repeated service restart events that may indicate repeated exploitation attempts.
  • Process: Sudden termination of the Pexip Infinity signalling process followed by automatic or manual service recovery.
  • Network: Anomalous or malformed WebRTC signalling messages originating from untrusted or unexpected source IPs targeting the Pexip Infinity signalling interface.

Mitigation and workarounds

Pexip has released version 39.0 which resolves this vulnerability; organizations running Pexip Infinity 35.0 through 38.1 should upgrade immediately (Pexip Security Bulletins). If immediate patching is not feasible, organizations should verify whether Direct Media for WebRTC is enabled — if this non-default feature is not in use, the risk is mitigated without configuration changes. As an additional control, implement network-level access controls to restrict signalling traffic to trusted sources only, and monitor system logs for unexpected abort events or service restarts that could indicate exploitation attempts.

Community reactions

The vulnerability received limited community attention, with automated CVE tracking accounts on Bluesky and Mastodon noting the disclosure. No significant vendor statements beyond the Pexip security bulletin or notable independent researcher commentary have been identified. Coverage has been limited to vulnerability aggregation sites and security news digests.

Additional resources


SourceThis report was generated using AI

Related Pexip Infinity Management Node vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59683CRITICAL9.1
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66379HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66378HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66377HIGH7.5
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025
CVE-2025-66443MEDIUM5.3
  • Pexip Infinity Management Node logoPexip Infinity Management Node
  • cpe:2.3:a:pexip:pexip_infinity
NoYesDec 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management