← back
CVE-2020-36946

SyncBreeze 10.0.28 - 'login' Denial of Service

CVSS 8.7 HIGHEPSS 0.6%CWE-770
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.7EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
27 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →