SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-10967

In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

MEDIUM 5.3EPSS 8.15%

Does this matter?

Lower severity and a low EPSS score (8.15%). Track it; it rarely justifies an emergency change on its own.

Description

In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
8.15% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
dovecot/dovecot
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.