Remote Software Abort Vulnerability in Pexip Infinity Software
CVE-2022-27930

5.9MEDIUM

Key Information:

Vendor

Pexip

Vendor
CVE Published:
17 July 2022

What is CVE-2022-27930?

A vulnerability exists in Pexip Infinity versions prior to 27.3, where remote attackers can trigger a software abort through the manipulation of the single-sign-on feature. By guessing a random Universally Unique Identifier (UUID), an attacker can cause the software to crash, disrupting services and potentially exposing sensitive information. This vulnerability highlights the importance of robust input validation and security measures in identity management systems.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-27930 : Remote Software Abort Vulnerability in Pexip Infinity Software