Remote Denial-of-Service Vulnerability in Sync Breeze and Disk Pulse by Flexense
CVE-2025-59895

8.2HIGH

What is CVE-2025-59895?

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 are susceptible to a remote denial-of-service vulnerability linked to inadequate validation of user input during the configuration restore process. Exploitation of this vulnerability could enable malicious actors to submit harmful requests that alter the configuration file. Consequently, this may lead to the application becoming unresponsive, and in certain instances, may require complete reinstallation since the corrupted configuration prevents the service from starting, even when attempts are made to restart it manually.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Disk Pulse Enterprise v10.4.18

Sync Breeze Enterprise Server v10.4.18

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.