nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-53873 CVE-2023-53873
HIGH
SyncBreeze 15.2.24 Denial of Service via Login Endpoint Overflow
Record summary
CVE-2023-53873 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availability.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SyncBreezeBrowse Syncbreeze / SyncBreeze | CVE List | 15.2.24 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSyncBreeze 15.2.24 - 'login' Denial of ServiceExploitDB exploitby mohamed youssefNot analyzed1 file
References
4ExploitDB-51725exploit
https://www.exploit-db.com/exploits/51725 SyncBreeze Product Webpageproduct
https://www.syncbreeze.com/ VulnCheck Advisory: SyncBreeze 15.2.24 Denial of Service via Login Endpoint OverflowThird-party advisory
https://www.vulncheck.com/advisories/syncbreeze-denial-of-service-via-login-endpoint-overflow