Impact
An attacker who possesses valid credentials can issue an IMAP LIST command that consumes excessive CPU. The resulting resource exhaustion can degrade performance or completely deny IMAP service to legitimate users. The vulnerability is both an uncontrolled resource consumption flaw (CWE‑400) and an improper input validation issue (CWE‑606).
Affected Systems
The flaw affects Open‑Xchange Dovecot Community Edition and Pro. Specific version details are not disclosed in the available data.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium‑severity risk. The EPSS score is < 1% (0.0029), indicating a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. Because it requires valid credentials, the attack vector is credential‑based; the attacker must obtain or compromise an account before abusing the LIST command. Publicly documented exploits are not known, so exploitation is likely manual or automated only after authentication.
OpenCVE Enrichment