Impact
An attacker who possesses legitimate credentials can choose a memory‑intensive compression algorithm for an IMAP session. Opening several such sessions exhausts the process memory, causing the IMAP login process to terminate and disconnect all associated sessions. This leads to service degradation or a complete denial of IMAP availability. The vulnerability is an instance of CWE-400 (Uncontrolled Resource Consumption) and CWE-770 (Memory Leak).
Affected Systems
Open‑Xchange GmbH’s OX Dovecot Community Edition and Professional Edition are affected. The vulnerability applies to any installed version that enables IMAP compression; specific version numbers are not disclosed, so all releases using default compression settings should be treated as vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 6.5 places the issue in the moderate range, and no public exploits exist yet. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, since an attacker with valid credentials can force memory exhaustion, the risk of service disruption remains significant, especially for servers with high IMAP traffic. Based on the description, it is inferred that the primary attack vector requires legitimate authentication, typically through internal or compromised accounts.
OpenCVE Enrichment