CVE-2026-33603
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
| CWE | CWE-99 |
| Vendor | open-xchange gmbh |
| Product | ox dovecot pro |
| Published | May 12, 2026 |
| Last Updated | May 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for open-xchange gmbh ox dovecot pro
Be the first to know when new medium vulnerabilities affecting open-xchange gmbh ox dovecot pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Open-Xchange GmbH / OX Dovecot Pro
0 โค 3.1.0 0 โค 2.4.0