CVE-2025-59683 Details
Description
Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, leading to a denial of service.
A vulnerability exists in Pexip Infinity versions 15.0 through 38.0 prior to 38.1, specifically within the Secure Scheduler for Exchange service when used with Office 365 Legacy Exchange Tokens. This vulnerability allows remote attackers to read potentially sensitive data and excessively consume resources, leading to a denial-of-service condition.
Users running Pexip Infinity Version 37.1 or newer should ensure that all Secure Scheduler for Exchange integrations are using an 'Add-in authentication token type' of 'SSO Token' or 'NAA (Nested App Authentication) Token'. For versions prior to 37.1, upgrading to Pexip Infinity v38.1 is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.pexip.com/admin/security_bulletins.htm | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pexip pexip infinity | >= 15, < 38.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 5, 2026 | Reanalysis | [email protected] |
| Jan 5, 2026 | Initial Analysis | [email protected] |
| Dec 25, 2025 | New CVE Received | [email protected] |