Impact
An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authentication. If the server runs in high-security mode only the attacker's connection is terminated; in high-performance mode all connections handled by the same managesieve-login process are destroyed. Repeating the attack repeatedly leads to denial of service for Sieve script management.
Affected Systems
The vulnerability affects Open‑Xchange GmbH’s OX Dovecot Community Edition and Pro Edition. No specific version information is listed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity issue. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires network access to the ManageSieve service and can be performed without authentication. An attacker may cause a full process crash or partial service disruption depending on the operating mode.
OpenCVE Enrichment