Impact
A maliciously crafted email can be interpreted as dsync protocol commands when an administrator runs the dsync stream protocol during migration or replication. The injected commands can alter internal mailbox attributes that normal users are not allowed to set, thereby enabling an attacker to modify mailbox state or cause dsync errors. The flaw does not provide remote code execution, but it directly compromises mailbox integrity and availability.
Affected Systems
The vulnerability affects Open‑Xchange Dovecot Community Edition and Open‑Xchange Dovecot Professional. All releases published before the fix are potentially vulnerable; no specific version information is provided in the advisory.
Risk and Exploitability
The CVSS base score of 4.8 indicates a moderate impact. The EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting limited widespread exploitation. The attack vector requires an administrator to run dsync with the stream protocol on mailboxes that contain untrusted content, typically during migration or replication. As a result, the risk is mainly insider or post‑compromise, with moderate severity once triggered.
OpenCVE Enrichment