← Vulnerability feed

Vulnerability record · CVE-2018-8065 · published 12 March 2018

CVE-2018-8065: Flexense SyncBreeze Enterprise web server input validation DoS

Flexense · Syncbreeze

The SyncBreeze Enterprise 10.6.24 web server mishandles HTTP input, causing a user mode write access violation in the syncbrs.exe memory region. Rapidly sending requests with long HTTP header values or long URIs crashes the service, disrupting availability.

7.5 CVSS 3.0 High EPSS 76% · top 0.5% CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be triggered by rapidly sending a variety of HTTP requests with long HTTP header values or long URIs.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.5 with no authentication or user interaction required and a very high EPSS score, though impact is limited to denial of service.

What it is

The SyncBreeze Enterprise 10.6.24 web server mishandles HTTP input, causing a user mode write access violation in the syncbrs.exe memory region. Rapidly sending requests with long HTTP header values or long URIs crashes the service, disrupting availability.

Impact

An unauthenticated remote attacker can crash the SyncBreeze web server process, causing a denial of service. No data confidentiality or integrity impact is indicated by the CVSS vector.

Attack surface

Reachable over the network through the SyncBreeze HTTP web server; the CVSS vector shows no privileges or user interaction required. The flaw is triggered by crafted HTTP requests with oversized headers or URIs.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.75875, 99.5th percentile) and public references include a Packet Storm advisory, a GitHub PoC, and a Metasploit pull request, indicating public exploit tooling exists.

What to do

  • Upgrade SyncBreeze Enterprise to a version later than 10.6.24 if the vendor provides a fix; no fixed version is stated in this record.
  • If patching is not possible, restrict network access to the SyncBreeze web server to trusted hosts only.
  • Place the web server behind a reverse proxy or WAF that rejects oversized HTTP headers and URIs.
  • Monitor the syncbrs.exe process and configure automatic restart or alerting on crash.
  • Review vendor advisories for an official fix, since this record does not name one.

Detection

  • Alert on syncbrs.exe process crashes or unexpected restarts in Windows event logs.
  • Monitor HTTP request logs for unusually long header values or URIs targeting the SyncBreeze web server.
  • Watch for high-volume or rapid HTTP request bursts from a single source to the SyncBreeze service.
  • Use the public PoC and Metasploit module references to build test signatures for known exploit traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-8065 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-6537Flexense syncbreeze memory buffer overflow vulnerabilityA buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code …EPSS 4.2%9.8CVE-2017-13696Flexense Enterprise Products Web Server GET Request Buffer OverflowA buffer overflow in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk P…EPSS 78%analysed9.8CVE-2017-14980Flexense syncbreeze memory buffer overflow vulnerabilityBuffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.EPSS 22%8.8CVE-2017-17996Flexense syncbreeze memory buffer overflow vulnerabilityA buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14. The vulnerability can be triggere…EPSS 5.1%8.7CVE-2020-36946Flexense syncbreeze allocation without limits vulnerabilitySyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can …EPSS 0.73%8.5CVE-2020-37100Flexense syncbreeze unquoted search path vulnerabilitySync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated sy…EPSS 0.20%8.5CVE-2025-59891Flexense diskpulse cross-site request forgery vulnerabilityCross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c…EPSS 0.15%8.5CVE-2025-59892Flexense diskpulse cross-site request forgery vulnerabilityCross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2018-8065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.