CVE-2013-10065
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
05/08/2025
Last modified:
02/10/2025
Description
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resulting in loss of availability. The flaw is triggered during the handling of malformed key exchange data, including a non-standard byte (\x28) in place of the expected SSH protocol delimiter.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sysax:multi_server:6.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/dos/windows/ssh/sysax_sshd_kexchange.rb
- https://www.mattandreko.com/2013/04/08/sysax-multi-server-6.10-ssh-dos/
- https://www.sysax.com/
- https://www.vulncheck.com/advisories/sysax-multi-server-sshd-key-exchange-dos
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/auxiliary/dos/windows/ssh/sysax_sshd_kexchange.rb
- https://www.mattandreko.com/2013/04/08/sysax-multi-server-6.10-ssh-dos/



