CVE-2012-10060: Sysax Multi Server
Critical severity, CVSS 9.8. EPSS: 4.3% chance of exploitation in the next 30 days.
Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-size stack buffer without proper bounds checking. This allows remote code execution under the context of the service.
Affected products
- Sysax Multi Server: before 5.55 (fixed in 5.55)
Published 2025-08-13. Last modified 2026-06-16.