CVE-2025-59683: Critical severity Pexip Infinity vulnerability
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59683?
CVE-2025-59683 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive data and lead to denial of service.
How do I fix CVE-2025-59683?
To fix CVE-2025-59683, update Pexip Infinity to version 38.1 or later, which addresses the improper access control in the Secure Scheduler for Exchange service.
What systems are affected by CVE-2025-59683?
CVE-2025-59683 affects Pexip Infinity versions 15.0 through 38.0 when used with Office 365 Legacy Exchange Tokens.
What are the risks associated with CVE-2025-59683?
The risks associated with CVE-2025-59683 include unauthorized data access and potential resource exhaustion leading to service outages.
Who can exploit CVE-2025-59683?
CVE-2025-59683 can be exploited by remote attackers who gain access to the affected service using Office 365 Legacy Exchange Tokens.