Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
对资源描述符的控制不恰当(资源注入)
Vulnerability Title
Open-Xchange OX Dovecot Pro 安全漏洞
Vulnerability Description
Open-Xchange OX Dovecot Pro是德国Open-Xchange公司的一个邮件存储与投递系统。 Open-Xchange OX Dovecot Pro存在安全漏洞,该漏洞源于攻击者可以使用特制的base64交换伪造SCRAM TLS通道绑定,可能导致中间人攻击窃听通信。
CVSS Information
N/A
Vulnerability Type
N/A