vendor:
Sysax Multi Server
by:
Shailesh Kumavat
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Sysax Multi Server
Affected Version From: Sysax Multi Server 5.50
Affected Version To: Sysax Multi Server 5.50
Patch Exists: YES
Related CWE: NA
CPE: a:sysax:sysax_multi_server:5.50
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2020
Sysax Multi Server 5.50 – Denial of Service (PoC)
A maliciously crafted crash.key file can cause a denial of service in Sysax Multi Server 5.50 when uploaded to the software. The software will crash and never run again.
Mitigation:
Ensure that the software is updated to the latest version and that all files uploaded to the software are from trusted sources.