Impact
The vulnerability occurs when IMAP compression is enabled on Open‑Xchange Dovecot servers. The same compression state is reused across IMAP responses within a single session, causing response sizes to vary depending on both the attacker’s mail and other emails present in the target mailbox. An attacker who can inject mail into a victim’s inbox and can observe the size of the victim’s IMAP traffic can use these size variations to confirm whether the body of a small message matches a guessed string. While arbitrary content recovery was not demonstrated, the attack can effectively disclose whether a secret‑like message body matches a candidate. The weakness is an information‑exposure flaw (CWE‑200 and CWE‑205).
Affected Systems
The affected vendors are Open‑Xchange GmbH, specifically the OX Dovecot CE and OX Dovecot Pro products. The vulnerability applies to versions that have IMAP compression enabled, but the precise version range is not specified in the advisory. Users should verify that their Dovecot deployment is running the latest non‑vulnerable release when available.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity under the current assessment. No publicly available exploits exist, and the EPSS score is < 1%, indicating a very low likelihood of exploitation. It is listed as not in the CISA KEV catalog. The most probable attack path requires an attacker to send email to the victim and monitor the victim’s IMAP traffic, which may be achievable in shared or compromised environments. Given the low CVSS but possible covert nature of the disclosure, administrators should address the issue promptly.
OpenCVE Enrichment