Impact
Compiled Sieve scripts in OX Dovecot track CPU consumption, but an attacker with valid credentials can reset this accounting by repeatedly activating different scripts. This loophole also leaves behind compiled script files when a script is deleted or renamed, allowing the configured CPU limit to be bypassed and enabling continuous high CPU use. The orphaned files grow disk space, both leading to service degradation for mail delivery.
Affected Systems
Vulnerable versions are found in Open‑Xchange GmbH's OX Dovecot Community Edition and Pro Edition. Specific version numbers are not publicly documented, so any installation of these products should be evaluated.
Risk and Exploitability
With a CVSS score of 3.1, the vulnerability is modestly serious, yet still presents a tangible risk of service disruption. Exploitation requires legitimate account credentials, limiting the threat to insiders or compromised accounts. No public exploits are known, and the EPSS score is <1%, indicating a very low exploitation probability. Because the issue can degrade mail delivery, administrators should consider the vulnerability a low‑to‑moderate risk depending on the criticality of the mail service.
OpenCVE Enrichment