Impact
The vulnerability allows an attacker with valid credentials to send specially crafted compressed IMAP data that causes the OX Dovecot authentication process to exhaust its stack and crash. The crash terminates the process, leading to degradation or denial of service for IMAP. This is a classic stack overflow or uncontrolled resource consumption flaw as defined by CWE-674.
Affected Systems
Affected products are Open‑Xchange GmbH OX Dovecot CE and Pro editions. No specific versions are listed in the CNA data, so any instance of these products potentially is at risk until a patched version is installed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker who has authenticated access to an IMAP client and can send compressed data; this requires valid credentials but can be achieved over the network. Given the lack of publicly available exploits, the immediate risk appears moderate, but the denial‑of‑service impact warrants prompt action.
OpenCVE Enrichment