← Vulnerability feed

Vulnerability record · CVE-2013-10065 · published 5 August 2025

CVE-2013-10065: Sysax multi server vulnerability

Sysax · Multi Server

A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange data, including a non-standard byte (\x28) in place of the expected SSH protocol delimiter.

8.7 CVSS 4.0 High EPSS 1.6% · top 24.7% CWE-248 · CWE-248
8.7CVSS 4.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange data, including a non-standard byte (\x28) in place of the expected SSH protocol delimiter.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-10065 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2012-10060Sysax multi server stack-based buffer overflow vulnerabilitySysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long us…EPSS 3.0%9.0CVE-2009-4790Sysax multi server path traversal vulnerabilityMultiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted…EPSS 3.9%8.8CVE-2020-13229Sysax multi server vulnerabilityAn issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authen…EPSS 1.6%7.5CVE-2024-53458Sysax multi server uncontrolled resource consumption vulnerabilitySysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.EPSS 0.52%7.1CVE-2012-6530Sysax Multi Server HTTP stack buffer overflow enables remote code executionSysax Multi Server before 5.52 contains a stack-based buffer overflow that is reachable when HTTP is enabled. A remote authenticated user holding the…EPSS 46%analysed6.5CVE-2020-23574Sysax multi server memory buffer overflow vulnerabilityWhen uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a le…EPSS 0.95%6.1CVE-2020-13228Sysax multi server cross-site scripting vulnerabilityAn issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.EPSS 3.1%5.4CVE-2024-53459Sysax multi server cross-site scripting vulnerabilitySysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2013-10065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.