← Vulnerability feed

Vulnerability record · CVE-2024-37917 · published 2 April 2025

CVE-2024-37917: Pexip infinity improper input validation vulnerability

Pexip · Pexip Infinity

Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.

7.5 CVSS 3.1 High EPSS 0.50% · top 59.5% CWE-20 · Improper input validation
7.5CVSS 3.1 base score
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (software abort) via a crafted signalling message.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37917 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-103110Pexip infinity out-of-bounds write vulnerabilityPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely…EPSS 0.61%9.8CVE-2020-11805Pexip infinity improper input validation vulnerabilityPexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.EPSS 1.4%9.8CVE-2015-4719Pexip infinity improper privilege management vulnerabilityThe client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.EPSS 1.5%9.8CVE-2017-6551Pexip infinity improper input validation vulnerabilityPexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Co…EPSS 3.5%9.4CVE-2026-103109Pexip infinity out-of-bounds write vulnerabilityPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attac…EPSS 0.24%9.1CVE-2025-59683Pexip infinity incorrect authorization vulnerabilityPexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Lega…EPSS 0.33%8.8CVE-2026-103105Pexip infinity incorrect authorization vulnerabilityPexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with …EPSS 0.18%8.6CVE-2026-103102Pexip infinity allocation without limits vulnerabilityPexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a softw…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2024-37917), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.