Impact
An attacker who can send mail to a user may craft a message header that causes the IMAP THREAD command to consume CPU disproportional to the message size. When a client requests a THREAD on the mailbox, the server can be overloaded, leading to degraded performance or denial of service. This vulnerability involves improper input validation (CWE‑606) and can trigger a denial of service through unexpected resource consumption (CWE‑400).
Affected Systems
The vulnerability affects Open‑Xchange Dovecot CE and Pro. Exact affected version numbers are not disclosed in the advisory, so any current release may be susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is 0.00272 and the vulnerability is not listed in KEV, indicating a low exploitation probability. However, because the attack requires the ability to send mail to the target, it is considered a targeted threat. If an adversary gains the capability to inject mail, the high CPU consumption can be triggered by issuing an IMAP THREAD command through a mail client. The low EPSS score suggests a lower exploitation probability, yet the impact on availability warrants immediate attention.
OpenCVE Enrichment