CVE-2023-54337
CRITICAL 9.1EPSS 0.5%
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.
- CVSS v4.0
- 5.1 MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H - CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H - EPSS
- 0.51% chance of exploitation in the next 30 days, 42th percentile
- Published
- 2026-01-13
- Updated
- 2026-03-05
Proof-of-concept exploits (2)
- https://www.exploit-db.com/exploits/51066
- https://www.vulncheck.com/advisories/sysax-multi-server-password-denial-of-service-poc