Impact
An attacker who can cause Dovecot to relay a message, for example through a Sieve redirect or a submission relay, can embed a crafted line ending in the message body. This bypasses the outbound protection that normally blocks message content from being interpreted as SMTP commands, allowing the downstream mail server to treat part of the message body as new SMTP commands and inject spoofed email. The vulnerability class is identical to CVE‑2023‑51764 and CVE‑2023‑51766. No publicly available exploits have been reported, but the flaw permits the creation of forged messages that appear to originate from legitimate senders.
Affected Systems
Affected products are the Open‑Xchange Dovecot CE and Open‑Xchange Dovecot Pro. The advisory indicates that any version before the vendor’s non‑vulnerable release is susceptible. Version information is not listed in the advisory, so all current releases lacking the fix should be considered vulnerable until updated.
Risk and Exploitability
The CVSS base score of 5.9 classifies the flaw as moderate severity. Because the attacker must be able to relay a message through Dovecot, the attack vector is likely remote but requires either an open relay or an authenticated session with relay capabilities. The exploit requires the downstream server not to have mitigated SMTP smuggling, so if the recipient system enforces stricter input validation the risk is reduced. The EPSS score is 0.00269 (less than 1%) and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of active exploitation, but the potential for message spoofing remains a concern for mail services that rely on Dovecot for outbound delivery.
OpenCVE Enrichment