Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33603

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 6.8

Описание

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.

A flaw was found in Dovecot. An attacker, positioned as a Man-in-the-Middle (MITM) between Dovecot and a client, can exploit a specially crafted base64 exchange to fake SCRAM TLS channel binding. This allows the attacker to eavesdrop on communications between Dovecot and the client, leading to information disclosure.

Меры по смягчению последствий

To reduce the risk of a Man-in-the-Middle attack, restrict network access to the Dovecot server. Configure firewalls to permit connections only from trusted networks and necessary client IP ranges. This limits an attacker's ability to intercept traffic. If firewall rules are modified, a service reload or restart may be required, which could temporarily disrupt active user sessions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotFix deferred
Red Hat Enterprise Linux 6dovecotFix deferred
Red Hat Enterprise Linux 8dovecotFix deferred
Red Hat Enterprise Linux 9dovecotFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-940
https://bugzilla.redhat.com/show_bug.cgi?id=2476464dovecot: Dovecot: Information disclosure via SCRAM TLS channel binding bypass

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
3 месяца назад

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.

CVSS3: 6.8
nvd
3 месяца назад

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.

CVSS3: 6.8
debian
3 месяца назад

Attacker can use a specially crafted base64 exchange between Dovecot a ...

CVSS3: 6.8
github
3 месяца назад

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость почтовых серверов Dovecot и OX Dovecot Pro, связанная с неправильным контролем идентификаторов ресурсов («внедрение ресурсов»), позволяющая нарушителю вызвать отказ в обслуживании

6.8 Medium

CVSS3