← Zuruck zu CVEs
CVE-2025-59683
HIGH8.2
Beschreibung
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.
CVE Details
CVSS v3.1 Bewertung8.2
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht12/25/2025
Zuletzt geandert1/5/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
pexip:pexip_infinity
Schwachen (CWE)
CWE-863
Referenzen
https://docs.pexip.com/admin/security_bulletins.htm(cve@mitre.org)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.