{"id":"CVE-2025-49088","title":"Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a craf…","summary":"Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a craf…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-617"],"vendor":"pexip","product":"pexip_infinity","affected":["pexip_infinity >= 32.0, < 37.2"],"patched":["pexip_infinity 37.2"],"published":"2025-12-25","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-49088","references":[{"url":"https://docs.pexip.com/admin/security_bulletins.htm","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00315,"epssPercentile":0.22064,"ingestedAt":"2026-09-30T23:29:32.511Z","slug":"CVE-2025-49088","body":"## Overview\n\nPexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.\n\n## Affected\n\n- `pexip_infinity >= 32.0, < 37.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `pexip_infinity 37.2`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}