Vulnerability Description
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sysax | Multi Server | 6.95 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/51066ExploitThird Party AdvisoryVDB Entry
- https://www.sysax.com/Product
- https://www.vulncheck.com/advisories/sysax-multi-server-password-denial-of-serviThird Party Advisory
- https://www.exploit-db.com/exploits/51066ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/sysax-multi-server-password-denial-of-serviThird Party Advisory
FAQ
What is CVE-2023-54337?
CVE-2023-54337 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with ...
How severe is CVE-2023-54337?
CVE-2023-54337 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-54337?
Check the references section above for vendor advisories and patch information. Affected products include: Sysax Multi Server.