
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-54337 is a denial of service (DoS) vulnerability in Sysax Multi Server version 6.95, affecting the administrative password field. Attackers can crash the application by submitting 800 bytes of repeated characters to the password field, disrupting server availability and functionality. The vulnerability was published on January 13, 2026, and has a CVSS v3.1 base score of 9.1 (Critical) with network-accessible attack vector and no authentication required (Feedly, Exploit-DB).
The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input), where the application fails to enforce appropriate length limits on the administrative password field (Feedly). An attacker can send a crafted network request overwriting the password field with approximately 800 bytes of repeated characters, triggering an application crash. No authentication or special privileges are required to exploit this vulnerability, and attack complexity is low. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB).
Successful exploitation results in a crash of the Sysax Multi Server application, causing a complete loss of availability for all services hosted on the server. There is no confidentiality or integrity impact in the CVSS v4.0 assessment, but the CVSS v3.1 scoring also notes high integrity impact, suggesting potential for data disruption. The attack is trivially executable by unauthenticated remote attackers, making it a significant operational risk for organizations relying on Sysax Multi Server for file transfer or related services (Feedly).
A public proof-of-concept exploit is available on Exploit-DB (EDB-51066), making this vulnerability easily weaponizable (Exploit-DB). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.022% (0.000220), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no patch is currently available from the vendor (Feedly).
'A' * 800) targeting the password input field.sysaxservd.exe or equivalent) without administrative action.No vendor patch is currently available for CVE-2023-54337 in Sysax Multi Server 6.95 (Feedly). Organizations should apply the following interim mitigations:
A technical write-up and PoC details were published on infinitsec.net shortly after the CVE was disclosed (infinitsec). The vulnerability was also noted by INCIBE-CERT (Spain's national cybersecurity incident response team) in their early warning alerts (INCIBE-CERT). Community discussion has been limited, reflecting the niche nature of the affected software.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."