MEDIUM🇬🇧 English

CVE-2026-33603

CVSS 6.8v3.1pub. 2026-05-12upd. 2026-05-18

Atakujący może wykorzystać specjalnie przygotowaną wymianę base64 między Dovecot a klientem, aby sfałszować SCRAM TLS channel binding. Wymaga to umożliwienia atakującemu pozycjonowania się między Dovecot a połączeniem klienta. W przypadku powodzenia atakujący może podsłuchiwać komunikację między Dovecot a klientem jako proxy MITM. Zainstaluj naprawioną wersję. Nie znane są publicznie dostępne exploity.

Pokaż oryginał (EN)

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.

CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Dovecot

    APP
    Dovecot
    < 2.4.4
  • Open Xchange Dovecot

    APP
    Open-Xchange
    < 3.1.5
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2019-11500CRITICAL9.8PL ✓ten sam produkt

Dovecot/Pigeonhole: RCE przez błędną obsługę znaków null w łańcuchach

CVE-2026-27851HIGH7.4ten sam produkt

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly i...

CVE-2026-24031HIGH7.7ten sam produkt

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerabil...

CVE-2025-59032HIGH7.5ten sam produkt

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to cras...

CVE-2026-27856HIGH7.4ten sam produkt

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An atta...