CVE-2012-10060

Severity CVSS v4.0:
CRITICAL
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
13/08/2025
Last modified:
24/09/2025

Description

Sysax Multi Server versions prior to 5.55 contains a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-size stack buffer without proper bounds checking. This allows remote code execution under the context of the service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sysax:multi_server:*:*:*:*:*:*:*:* 5.55 (excluding)