Impact
An attacker who possesses valid user credentials can trigger the vulnerability by sending an invalid IMAP URLFETCH command. The server mistakenly includes uninitialized memory data in the error response that is returned to the client. This allows disclosure of confidential process data and potentially other sensitive information, consistent with CWE-200 and CWE-908. The resulting impact is a loss of confidentiality.
Affected Systems
The affected components are Open-Xchange GmbH’s OX Dovecot CE and OX Dovecot Pro products. No specific vulnerable version numbers are listed, so any installation that has not been patched to a non‑vulnerable release remains at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of 0.226% indicates a very low likelihood of exploitation. The vulnerability is not included in the CISA KEV catalog, and no public exploits are known. Successful exploitation requires valid credentials to issue the malformed IMAP request, so an attacker must first obtain or compromise legitimate user access. Given the lack of public exploits and the credential requirement, the overall risk is moderate, but the data exposure remains a concern for organizations with sensitive information.
OpenCVE Enrichment