Количество 9
Количество 9
GHSA-7923-h3mf-4442
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
CVE-2026-27855
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
CVE-2026-27855
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
CVE-2026-27855
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known.
CVE-2026-27855
Dovecot OTP authentication is vulnerable to replay attack under specif ...
BDU:2026-10400
Уязвимость почтового сервера Dovecot, связанная с возможностью обхода процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260707-73-0040
Уязвимость dovecot
SUSE-SU-2026:1641-1
Security update for dovecot22
openSUSE-SU-2026:20554-1
Security update for dovecot24
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7923-h3mf-4442 Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-27855 Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-27855 Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-27855 Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authentication happens over unsecure connection, switch to SCRAM protocol. Alternatively ensure the communcations are secured, and if possible switch to OAUTH2 or SCRAM. No publicly available exploits are known. | CVSS3: 6.8 | 0% Низкий | 4 месяца назад | |
CVE-2026-27855 Dovecot OTP authentication is vulnerable to replay attack under specif ... | CVSS3: 6.8 | 0% Низкий | 4 месяца назад | |
BDU:2026-10400 Уязвимость почтового сервера Dovecot, связанная с возможностью обхода процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 6.8 | 0% Низкий | 4 месяца назад | |
ROS-20260707-73-0040 Уязвимость dovecot | CVSS3: 5.9 | 0% Низкий | 24 дня назад | |
SUSE-SU-2026:1641-1 Security update for dovecot22 | 3 месяца назад | |||
openSUSE-SU-2026:20554-1 Security update for dovecot24 | 4 месяца назад |
Уязвимостей на страницу