VulnerabilityModified
CVE-2023-54337
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application.
MEDIUM 5.1EPSS 0.54%
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1284
- Affected
- sysax/multi server
- Source
- disclosure@vulncheck.com
References
- https://www.exploit-db.com/exploits/51066Exploit, Third Party Advisory, VDB Entry
- https://www.sysax.com/Product
- https://www.vulncheck.com/advisories/sysax-multi-server-password-denial-of-service-pocThird Party Advisory
- https://www.exploit-db.com/exploits/51066Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/sysax-multi-server-password-denial-of-service-pocThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.