CVE-2024-38392

CRITICAL

Pexip Infinity Connect <1.13.0 - RCE

Title source: llm
STIX 2.1

Description

Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0037
EPSS Percentile 28.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Published Apr 02, 2025
Tracked Since Feb 18, 2026