CVE-2021-29656: Critical severity pexip infinity connect vulnerability
Published Feb 18, 2022
·Updated
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.
Affected Software
1 affected component
Pexip Infinity Connect<1.8.0
Event History
Feb 18, 2022
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
Description
Frequently Asked Questions
1
What is CVE-2021-29656?
CVE-2021-29656 is a vulnerability in Pexip Infinity Connect that mishandles TLS certificate validation.
2
What is the severity of CVE-2021-29656?
The severity of CVE-2021-29656 is rated as critical with a CVSS score of 9.8.
3
How does Pexip Infinity Connect before 1.8.0 handle TLS certificate validation?
Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation by not properly checking the allow list.
4
What software version is affected by CVE-2021-29656?
Pexip Infinity Connect versions up to but excluding 1.8.0 are affected by CVE-2021-29656.
5
Where can I find more information about CVE-2021-29656?
More information about CVE-2021-29656 can be found at the Pexip security bulletins page.