Description

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The issue is due to insufficient validation of user-supplied data during this process. An attacker could send malicious requests to alter the configuration file, causing the application to become unresponsive. In a successful scenario, the service may not recover on its own and require a complete reinstallation, as the configuration becomes corrupted and prevents the service from restarting, even manually.

INFO

Published Date :

2026-01-28T11:55:43.546Z

Last Modified :

2026-01-28T15:38:11.029Z

Source :

INCIBE
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59895 vulnerability.

Vendors Products
Flexense
  • Disk Pulse Enterprise
  • Diskpulse
  • Sync Breeze Enterprise Server
  • Syncbreeze
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-59895.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact