Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33605

Опубликовано: 28 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

A flaw was found in Dovecot. An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. This can lead to a denial of service for Sieve script management, affecting either the attacker's connection or all connections handled by the same process, depending on the security mode.

Меры по смягчению последствий

Restrict network access to the ManageSieve service to trusted clients only. This can be achieved by configuring a firewall to limit incoming connections to the service's port (e.g., 4190 for Sieve) from specific IP addresses or networks. For example, using firewalld:

firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_OR_NETWORK>" port port="4190" protocol="tcp" accept' firewall-cmd --reload

Replace <TRUSTED_IP_OR_NETWORK> with the actual trusted source. A firewall reload is required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dovecotAffected
Red Hat Enterprise Linux 6dovecotOut of support scope
Red Hat Enterprise Linux 7dovecotAffected
Red Hat Enterprise Linux 8dovecotAffected
Red Hat Enterprise Linux 9dovecotAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2525576dovecot: Dovecot: Denial of Service in ManageSieve login process

EPSS

Процентиль: 31%
0.00375
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
17 дней назад

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 7.5
nvd
17 дней назад

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

CVSS3: 7.5
debian
17 дней назад

An unauthenticated attacker can crash the ManageSieve login process by ...

CVSS3: 7.5
github
17 дней назад

An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.

suse-cvrf
12 дней назад

Security update for dovecot22

EPSS

Процентиль: 31%
0.00375
Низкий

7.5 High

CVSS3