Improper Access Control in Pexip Infinity Product by Pexip
CVE-2024-33850

4.3MEDIUM

Key Information:

Vendor

Pexip

Vendor
CVE Published:
10 June 2024

What is CVE-2024-33850?

Pexip Infinity versions prior to 34.1 are susceptible to an improper access control vulnerability that allows users in a waiting room to view the conference roster. This flaw enables unauthorized actions that should be restricted until users are formally admitted to the meeting, potentially exposing sensitive information and compromising the integrity of the conference setup.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.