4.9
CVSSv2

CVE-2020-24386

Published: 04/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.8 | Impact Score: 5.2 | Exploitability Score: 1.6
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

An issue exists in Dovecot prior to 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dovecot dovecot

debian debian linux 10.0

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #979363 dovecot: CVE-2020-24386 CVE-2020-25275 Package: src:dovecot; Maintainer for src:dovecot is Dovecot Maintainers <dovecot@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 5 Jan 2021 20:03:04 UTC Severity: grave Tags: security, upstream Found in ve ...
Several vulnerabilities have been discovered in the Dovecot email server CVE-2020-24386 When imap hibernation is active, an attacker (with valid credentials to access the mail server) can cause Dovecot to discover file system directory structures and access other users' emails via specially crafted commands CVE-2020-25275 Inn ...
A security issue was discovered in dovecot version 2226 up to 23113 When imap hibernation is active, an attacker can cause dovecot to discover the file system directory structure and access other users' emails using a specially crafted command The attacker must have valid credentials to access the mail server The issue is fixed in dovecot v ...