vendor:
SyncBreeze
by:
Ahmed Elkhressy
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: SyncBreeze
Affected Version From: 10.0.28
Affected Version To: 10.0.28
Patch Exists: Yes
Related CWE: N/A
CPE: a:syncbreeze:syncbreeze:10.0.28
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7, Windows 10
2020
SyncBreeze 10.0.28 – ‘login’ Denial of Service (Poc)
SyncBreeze 10.0.28 is vulnerable to a denial of service attack when a maliciously crafted HTTP POST request is sent to the login page. The payload of 1000 'A' characters causes the application to crash.
Mitigation:
Ensure that the application is updated to the latest version of SyncBreeze 10.0.28.