Impact
An authenticated attacker can submit a Sieve script containing an extreme numeric literal to the ManageSieve service. The service compiles the script and writes beyond the bounds of its buffer, corrupting memory and causing the ManageSieve process to crash. The observed crash constitutes a denial of service for script management, and the memory corruption could be exploited to achieve remote code execution, although no public exploits are presently known.
Affected Systems
The vulnerability affects Open‑Xchange SaaS products OX Dovecot CE and OX Dovecot Pro. No specific version numbers are provided in the advisory, so all versions that include the ManageSieve module are potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting limited exploitation activity. The attack requires valid credentials, so the vector is authenticated remote. While the primary impact is service disruption, the presence of a memory corruption flaw raises the risk of remote code execution should an attacker discover or develop an exploit. In the absence of publicly available exploits, the immediate risk is denial of service, but active monitoring is advisable.
OpenCVE Enrichment