CVE-2025-59895 - CVE House
Back to Database
Status published High CVE-2025-59895

Remote denial-of-service (DoS) vulnerability in Sync Breeze Enterprise Server

Vulnerability Description

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The issue is due to insufficient validation of user-supplied data during this process. An attacker could send malicious requests to alter the configuration file, causing the application to become unresponsive. In a successful scenario, the service may not recover on its own and require a complete reinstallation, as the configuration becomes corrupted and prevents the service from restarting, even manually.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59895

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Rafael Pedrero

Affected Vendor

Affected Software

Sync Breeze Enterprise Server, Disk Pulse Enterprise
Vulnerable Versions:
v10.4.18

Timeline

Official Publish: January 28th, 2026
Last Modified: January 28th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)