Impact
Dovecot’s authentication fields can be overwritten by data forwarded from a host that is listed as a trusted proxy. This flaw allows an attacker controlling such a proxy to inject values into the internal authentication record, enabling them to authenticate as any user without knowing the user’s password. The vulnerability operates when the deployment’s password database permits authentication without a password based on these fields.
Affected Systems
The issue affects Open‑Xchange OX Dovecot CE and OX Dovecot Pro installations that have configured trusted proxy networks. Deployments that do not enable trusted proxies are not affected. The flaw is present in versions prior to the non‑vulnerable update released by Open‑Xchange.
Risk and Exploitability
With a CVSS score of 4.3, the severity is moderate. No publicly known exploits exist and the EPSS score is <1% (approximately 0.0019), indicating a low current exploit probability. The flaw is not listed in CISA’s KEV catalog. Attackers must be able to act as a trusted proxy, which typically requires network access to the mail server or compromise of a host within the trusted proxy list. Once this condition is met, they can authenticate as any user, potentially accessing or exfiltrating private mail data.
OpenCVE Enrichment