Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://docs.pexip.com/admin/security_bulletins.htm |
|
Mon, 05 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pexip pexip Infinity
|
|
| CPEs | cpe:2.3:a:pexip:pexip_infinity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pexip pexip Infinity
|
Fri, 26 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Dec 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service. | |
| First Time appeared |
Pexip
Pexip infinity |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pexip
Pexip infinity |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-26T14:51:57.340Z
Reserved: 2025-09-18T00:00:00.000Z
Link: CVE-2025-59683
Updated: 2025-12-26T14:49:22.702Z
Status : Analyzed
Published: 2025-12-25T05:16:07.900
Modified: 2026-01-05T19:07:06.153
Link: CVE-2025-59683
No data.
OpenCVE Enrichment
No data.