CVE-2025-59683 - CVE House
Back to Database
Status published High CVE-2025-59683

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access...

Vulnerability Description

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59683

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Infinity
Vulnerable Versions:
15.0

Timeline

Official Publish: December 25th, 2025
Last Modified: December 26th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Weaknesses (CWE)