CVE-2025-59895

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The issue is due to insufficient validation of user-supplied data during this process. An attacker could send malicious requests to alter the configuration file, causing the application to become unresponsive. In a successful scenario, the service may not recover on its own and require a complete reinstallation, as the configuration becomes corrupted and prevents the service from restarting, even manually.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:flexense:diskpulse:10.4.18:*:*:*:enterprise:*:*:*
cpe:2.3:a:flexense:syncbreeze:10.4.18:*:*:*:enterprise:*:*:*

History

17 Jun 2026, 09:46

Type Values Removed Values Added
Summary
  • (es) Sync Breeze Enterprise Server v10.4.18 y Disk Pulse Enterprise v10.4.18 contienen una vulnerabilidad de denegación de servicio (DoS) remota en la funcionalidad de restauración de configuración. El problema se debe a una validación insuficiente de los datos proporcionados por el usuario durante este proceso. Un atacante podría enviar solicitudes maliciosas para alterar el archivo de configuración, provocando que la aplicación deje de responder. En un escenario exitoso, el servicio podría no recuperarse por sí solo y requerir una reinstalación completa, ya que la configuración se corrompe e impide que el servicio se reinicie, incluso manualmente.

10 Feb 2026, 21:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Flexense syncbreeze
Flexense diskpulse
Flexense
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-flexense-products - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-flexense-products - Third Party Advisory
CPE cpe:2.3:a:flexense:syncbreeze:10.4.18:*:*:*:enterprise:*:*:*
cpe:2.3:a:flexense:diskpulse:10.4.18:*:*:*:enterprise:*:*:*

28 Jan 2026, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 12:15

Updated : 2026-06-17 09:46


NVD link : CVE-2025-59895

Mitre link : CVE-2025-59895

CVE.ORG link : CVE-2025-59895


JSON object : View

Products Affected

flexense

  • diskpulse
  • syncbreeze
CWE
CWE-20

Improper Input Validation