Record summary

CVE-2020-36946 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List10.0.28affected

Proofs of concept

1

Catalogued exploits

ExploitDBSyncBreeze 10.0.28 - 'login' Denial of Service (Poc)ExploitDB exploitby Ahmed ElkhressyNot analyzed1 file
ExploitDB

PoC details

References

4