CVE-2014-8779: High severity pexip infinity vulnerability
Pexip Infinity before 8 uses the same SSH host keys across different customers' installations, which allows man-in-the-middle attackers to spoof Management and Conferencing Nodes by leveraging these keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8779?
CVE-2014-8779 has a medium severity rating due to the potential for man-in-the-middle attacks across different installations.
How do I fix CVE-2014-8779?
To fix CVE-2014-8779, update Pexip Infinity to version 8 or later to ensure unique SSH host keys for each installation.
What impact does CVE-2014-8779 have on my system?
CVE-2014-8779 allows attackers to spoof Management and Conferencing Nodes by exploiting shared SSH host keys, potentially compromising communications.
Which versions of Pexip Infinity are affected by CVE-2014-8779?
Pexip Infinity versions prior to 8, including all versions up to 7.0, are affected by CVE-2014-8779.
Is my data at risk with CVE-2014-8779?
Yes, if you are using an affected version of Pexip Infinity, your data is at risk of interception and spoofing by attackers due to shared SSH keys.