Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59032

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
Версия до 2.4.3 (исключая)
cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:*
Версия до 3.1.3 (исключая)

EPSS

Процентиль: 49%
0.00703
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo
CWE-229

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
redhat
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL in ...

CVSS3: 7.5
github
4 месяца назад

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость почтового сервера Dovecot, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 49%
0.00703
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo
CWE-229