Impact
An attacker who has valid credentials can open a large number of connections to the imap-hibernate service and send malformed commands. This triggers an out-of-bounds read that crashes the process. The crash interrupts hibernated IMAP sessions and can degrade the availability of the IMAP service.
Affected Systems
The vulnerability affects Open‑Xchange Dovecot Community Edition and Open‑Xchange Dovecot Professional. No specific version information is provided.
Risk and Exploitability
The reported CVSS score of 4.3 indicates a moderate impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid credentials, and no publicly available exploits are known. Detection would rely on observing abnormal connection patterns and repeated crashes, but after a fix the risk is effectively mitigated.
OpenCVE Enrichment