Sysax develops a focused multi-server product line that handles file transfer, remote access, and data management functions across enterprise deployments, presenting a modestly represented but notably prominent vulnerability footprint. Its vulnerabilities skew toward serious outcomes with an elevated share reaching critical severity and a strong tendency toward public exploit availability, while recurrent weakness classes including path traversal, cross-site scripting, buffer boundary violations, and input validation flaws reflect the complexity of parsing and access control in file-transfer and session-management code. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sysax over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6530HIGH Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code v | Jan 31, 2013 | 7.1 | 66 | NO | YES |
CVE-2012-10060CRITICAL Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, t | Aug 13, 2025 | 9.8 | 42 | NO | YES |
CVE-2013-10065HIGH A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key exchange packet can trigger a crash in the service, resu | Aug 5, 2025 | 7.5 | 40 | NO | YES |
CVE-2009-4790HIGH Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. NOTE: the prove | Apr 22, 2010 | 9.0 | 39 | NO | YES |
CVE-2023-54337CRITICAL Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the | Jan 13, 2026 | 9.1 | 28 | NO | NO |
CVE-2020-13229HIGH An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token. | Jun 2, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-13228MEDIUM An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. | Jun 2, 2020 | 6.1 | 25 | NO | YES |
CVE-2020-23574MEDIUM When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This | Aug 19, 2020 | 6.5 | 23 | NO | NO |
CVE-2009-4800MEDIUM Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command. | Apr 22, 2010 | 4.0 | 22 | NO | YES |
CVE-2024-53458HIGH Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets. | Mar 5, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sysax.
Media articles that mention a CVE ID that affects a product developed by Sysax — matched by CVE ID, not by vendor name.