Impact
An attacker who does not need to authenticate can send an IMAP ID command containing an unusually large number of parameters before logging in. The command causes the imap-login process to allocate increasing amounts of memory and CPU time, leading to out‑of‑memory conditions that terminate the process and all other connections it handles. The result is a service disruption that can effectively deny IMAP logins to legitimate users.
Affected Systems
Open‑Xchange’s OX Dovecot CE and OX Dovecot Pro are affected. No specific vulnerable version numbers are listed; any version running the described code path is potentially impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high level of severity. The EPSS score is < 1% and the vulnerability is not recorded in the CISA KEV catalog, but the lack of public exploits does not reduce the risk. The likely attack vector is a remote network connection that can issue IMAP commands before authentication, enabling an unauthenticated attacker to trigger resource exhaustion and cause denial of service.
OpenCVE Enrichment