vendor:
SyncBreeze
by:
Manuel García Cárdenas
7,5
CVSS
HIGH
Remote Denial of Service
119
CWE
Product Name: SyncBreeze
Affected Version From: SyncBreeze <= 10.2.12
Affected Version To: SyncBreeze <= 10.2.12
Patch Exists: YES
Related CWE: CVE-2017-17088
CPE: a:syncbreeze:syncbreeze:10.2.12
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
SyncBreeze <= 10.2.12 - Denial of Service
The Enterprise version of SyncBreeze is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server request in the Host header on making a connection, resulting in a classic Buffer Overflow that causes a Denial of Service. To exploit the vulnerability only is needed use the version 1.1 of the HTTP protocol to interact with the application.
Mitigation:
Vendor release 10.3 version