CVE-2020-25868: Input Validation
Published Jul 7, 2021
·Updated
Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service).
Affected Software
1 affected component
Pexip Pexip Infinity>=22.0<24.2
Event History
Jul 7, 2021
CVE Published
via MITRE·01:42 PM
Data Sourced
via MITRE·01:42 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25868?
CVE-2020-25868 is a vulnerability in Pexip Infinity 22.x through 24.x before 24.2 that allows an unauthenticated remote attacker to trigger a software abort, resulting in a temporary loss of service.
2
How severe is CVE-2020-25868?
CVE-2020-25868 has a severity rating of 7.5 (high).
3
How does CVE-2020-25868 affect Pexip Infinity?
CVE-2020-25868 affects Pexip Infinity versions 22.x through 24.x before 24.2.
4
How can an attacker exploit CVE-2020-25868?
An unauthenticated remote attacker can exploit CVE-2020-25868 by triggering a software abort during call setup, causing a temporary loss of service.
5
Is there a fix for CVE-2020-25868?
Yes, upgrading Pexip Infinity to version 24.2 or later will fix CVE-2020-25868.