Sysax Multi Server Denial-of-Service Vulnerability via Crafted SSH Packets

Vulnerability

A denial-of-service vulnerability has been identified in Sysax Multi Server version 6.99. The issue arises when the server processes specially crafted SSH packets, leading to a crash of the SSH service.

Impact

Exploitation of this vulnerability causes the SSH service to crash, disrupting any active connections and potentially causing a temporary denial of service on the affected system.

Reproduction

The vulnerability can be reproduced by sending specially crafted SSH packets to the Sysax Multi Server SSH port. This can be done using a compiled C program that creates a TCP connection to the server, sends an SSH banner, and then transmits the crafted packets. After sending the payload, the SSH service will crash, demonstrating the denial-of-service condition.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
2.5
exploitability
9.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.