CVE-2011-3372

Cyrus IMAPd <2.4.12 - Auth Bypass

Title source: llm

Description

imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.

Scores

EPSS 0.0075
EPSS Percentile 72.9%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

cyrus/imapd < 2.4.11

Timeline

Published Dec 24, 2011
Tracked Since Feb 18, 2026