CVE-2023-54337
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 9.1
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.01%
- CWE
- CWE-1284
- Published
- 2026-01-13
- Last modified
- 2026-03-13
Affected products
- Sysax Sysax Multi Server
Weakness type
Related vulnerabilities
- CVE-2025-9316 — N-central unauthenticated sessionID generation
- CVE-2026-87470 — Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to pote
- CVE-2026-21485 — iccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()
- CVE-2025-8320 — Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability
- CVE-2025-15080 — Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in Mitsubishi Electric proprietary protocol communication and SLMP communication for FA products
- CVE-2025-14869 — Improper Validation of Specified Quantity in Input in GitLab
- CVE-2025-8424 — Improper access control on the NetScaler Management Interface
- CVE-2025-61938 — BIG-IP Advanced WAF and ASM bd process vulnerability