Vulnerability Details CVE-2017-17088
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header on making a connection, resulting in a classic Buffer Overflow that causes a Denial of Service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.303
EPSS Ranking 96.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-17088
-
cpe:2.3:a:flexense:syncbreeze:10.0.28
-
cpe:2.3:a:flexense:syncbreeze:10.1
-
cpe:2.3:a:flexense:syncbreeze:10.1.16
-
cpe:2.3:a:flexense:syncbreeze:10.2.12
-
cpe:2.3:a:flexense:syncbreeze:9.5.16
-
cpe:2.3:a:flexense:syncbreeze:9.9.16