Impact
The comparison routine used by doveadm to validate passwords and API keys performs an incomplete timing‑safe check, allowing an attacker who can generate repeated requests to the service and measure the response time to deduce the exact length of the configured secret. The secret value itself is never revealed, but knowing its length significantly reduces the effort required to brute‑force the key, thereby raising the confidentiality risk of the system.
Affected Systems
Open‑Xchange GmbH’s OX Dovecot Community Edition and Professional Edition are affected. No specific vulnerable version numbers are listed in the given data, so any installation of OX Dovecot that has the doveadm API enabled and is reachable on the network should be treated as potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score is 3.1, indicating very low severity, and the EPSS score is < 1%, indicating a very low probability that this vulnerability is being actively exploited. The vulnerability is not catalogued in CISA’s KEV database. Attackers need physical or network proximity to the doveadm service, the ability to craft repeated queries, and a timing measurement tool. No publicly available exploits are known, so the threat is mostly theoretical; once the secret length is known, subsequent attacks such as brute‑force become easier.
OpenCVE Enrichment