CVE-2024-37917: Input Validation
Published Apr 2, 2025
·Updated
Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.
Affected Software
2 affected components
Pexip Infinity<35.0
Pexip Pexip Infinity<35.0
Event History
Apr 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37917?
The severity of CVE-2024-37917 is categorized as critical due to its potential to cause a denial of service.
2
How do I fix CVE-2024-37917?
To fix CVE-2024-37917, update your Pexip Infinity software to version 35.0 or later.
3
Who is affected by CVE-2024-37917?
Pexip Infinity users running versions prior to 35.0 are affected by CVE-2024-37917.
4
What type of vulnerability is CVE-2024-37917?
CVE-2024-37917 is an input validation vulnerability that can lead to a denial of service.
5
Can CVE-2024-37917 be exploited remotely?
Yes, CVE-2024-37917 can be exploited remotely by sending crafted signaling messages.