← Vulnerability feed

Vulnerability record · CVE-2015-4719 · published 24 September 2020

CVE-2015-4719: Pexip infinity improper privilege management vulnerability

Pexip · Pexip Infinity

The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.

9.8 CVSS 3.1 Critical EPSS 1.5% · top 27.4% CWE-269 · Improper privilege management
9.8CVSS 3.1 base score, v2 7.5
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-4719 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-11805Pexip infinity improper input validation vulnerabilityPexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.EPSS 1.4%9.8CVE-2017-6551Pexip infinity improper input validation vulnerabilityPexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Co…EPSS 3.5%9.1CVE-2025-59683Pexip infinity incorrect authorization vulnerabilityPexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Lega…EPSS 0.33%8.2CVE-2022-26656Pexip infinity vulnerabilityPexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via One Touch Join.EPSS 1.1%8.2CVE-2022-27933Pexip infinity vulnerabilityPexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.EPSS 1.1%7.5CVE-2025-66377Pexip infinity missing authentication for critical function vulnerabilityPexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access…EPSS 0.21%7.5CVE-2025-66378Pexip infinity incorrect authorization vulnerabilityPexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams …EPSS 0.25%7.5CVE-2025-66379Pexip infinity vulnerabilityPexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a cr…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2015-4719), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.