CVE-2014-3430
Dovecot - Authentication Bypass
Title source: ruleDescription
Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.
References (14)
Scores
EPSS
0.0835
EPSS Percentile
92.2%
Classification
CWE
CWE-287
Status
draft
Affected Products (50)
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
dovecot/dovecot
... and 35 more
Timeline
Published
May 14, 2014
Tracked Since
Feb 18, 2026