Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31039
HistoryJun 23, 2021 - 6:40 p.m.

Command Injection

2021-06-2318:40:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
dovecot
vulnerability
command injection
smtp
on-path attacker
plaintext commands
starttls
smtp submission service

EPSS

0.005

Percentile

77.0%

dovecot is vulnerable to command injection. On-path attacker could inject plaintext commands before STARTTLS negotiation that would be executed after STARTTLS finished with the client. Only the SMTP submission service is affected.