CVE 7.5 HIGH

CVE-2025-59032_CVE-2025-59032

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed version. No publicly available exploits are known.

Basic Information

ID CVE-2025-59032
Source OX
Published Mar 27, 2026 at 08:10
Modified Mar 27, 2026 at 19:42

Affected Product

Vendor Open-Xchange GmbH
Product OX Dovecot Pro
Affected Versions Open-Xchange GmbH OX Dovecot Pro 0
Open-Xchange GmbH OX Dovecot Pro 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.