CVE-2022-25357: Medium severity pexip infinity vulnerability
Published Jul 17, 2022
·Updated
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.
Affected Software
1 affected component
Pexip Pexip Infinity>=27.0<27.2
Event History
Jul 17, 2022
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25357?
CVE-2022-25357 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-25357?
To fix CVE-2022-25357, upgrade Pexip Infinity to version 27.2 or later.
3
What type of vulnerability is CVE-2022-25357?
CVE-2022-25357 is categorized as an Improper Access Control vulnerability.
4
Who is affected by CVE-2022-25357?
CVE-2022-25357 affects Pexip Infinity versions 27.0 and earlier.
5
Can an attacker exploit CVE-2022-25357 without a PIN?
Yes, an attacker can exploit CVE-2022-25357 to join a locked conference that does not require a PIN.