216.73.216.226

CVE-2025-59683

· Published 25/12/2025 05:16 · Modified 25/12/2025 05:16

Labels: CVE-2025-59683 2025-12-25CVE-2025-59683CWE-863[email protected]

Essential information

Published
25/12/2025 05:16
Modified
25/12/2025 05:16
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

CVSS metrics

Description

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pexip / pexip infinity cpe:2.3:a:pexip:pexip_infinity:*:*:*:*:*:*:*:*

References