Description
SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availability.
Problem types
Uncontrolled Resource Consumption
Product status
Credits
mohamed youssef
References
www.exploit-db.com/exploits/51725 (ExploitDB-51725)
www.syncbreeze.com/ (SyncBreeze Product Webpage)
www.vulncheck.com/...-of-service-via-login-endpoint-overflow (VulnCheck Advisory: SyncBreeze 15.2.24 Denial of Service via Login Endpoint Overflow)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.