ZeroHour

CVE-2025-59032

CVSS 3.1
7.5 high
EPSS
<1%p51
Published
()
Modified
Description

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

Vendors
dovecotopen-xchange
Products
dovecot
Weakness
CWE-20, CWE-229
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.