Impact
An attacker who can reach the ManageSieve service without authentication can send a truncated quoted argument during login, causing the process to enter an infinite loop and consume CPU cycles relentlessly. This resource exhaustion leads to service degradation for Sieve script management, and sustaining the attack can exhaust the host’s entire CPU, effectively denying service to legitimate users.
Affected Systems
The vulnerability applies to Open‑Xchange GmbH’s OX Dovecot Community Edition product. No specific version range is provided in the advisory, so any installation of OX Dovecot CE that includes the vulnerable ManageSieve component should be considered at risk.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate severity. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. An attacker can exploit the flaw by connecting directly to the ManageSieve port, sending a malformed command, and looping the server into a high‑CPU state. The attack requires network access to the service and does not depend on privileged credentials, making it a threat to publicly reachable SMTP servers that expose ManageSieve.
OpenCVE Enrichment