Vulnerability Description
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pexip | Pexip Infinity | < 39.0 |
Related Weaknesses (CWE)
References
- https://docs.pexip.com/admin/security_bulletins.htmVendor Advisory
FAQ
What is CVE-2025-66377?
CVE-2025-66377 is a vulnerability with a CVSS score of 7.5 (HIGH). Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinit...
How severe is CVE-2025-66377?
CVE-2025-66377 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66377?
Check the references section above for vendor advisories and patch information. Affected products include: Pexip Pexip Infinity.