CVE-2020-10957
Dovecot vulnerability analysis and mitigation

Overview

In Dovecot before version 2.3.10.1, a security vulnerability was discovered where unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp services. The vulnerability was assigned CVE-2020-10957 and was discovered by Philippe Antoine from Catena Cyber. The issue was reported on March 24, 2020, and fixed on April 2, 2020, with public disclosure on May 18, 2020. The vulnerability affects Dovecot versions 2.3.0 through 2.3.10 (Openwall OSS, Dovecot Security).

Technical details

The vulnerability is classified as a NULL pointer dereference (CWE-476) with a CVSS v3.1 score of 7.5 (High). The issue occurs when a client sends a NOOP command with an invalid string parameter, particularly when the parameter doesn't start with a double quote. This vulnerability can be triggered by sending commands like NOOP EE"FY to the submission port. The high severity score is due to the attack vector being network-accessible (AV:N), requiring low attack complexity (AC:L), no privileges (PR:N), and no user interaction (UI:N), with impact limited to availability (A:H) (Openwall OSS).

Impact

The primary impact of this vulnerability is a denial of service condition. A remote attacker can keep the submission-login service down by repeatedly exploiting this vulnerability. For LMTP service, the risk is considered negligible as it is typically deployed behind a trusted MTA. The vulnerability affects the availability of the service but does not compromise confidentiality or integrity (Openwall OSS).

Exploitability

The vulnerability is highly exploitable as it requires no authentication and can be triggered remotely by sending malformed NOOP commands to the submission port. This makes it particularly dangerous for the submission-login service, which can be targeted without authentication. A proof of concept exists involving sending the command NOOP EE"FY to the submission port (Openwall OSS, PacketStorm).

Mitigation and workarounds

The primary mitigation is to upgrade to Dovecot version 2.3.10.1 or later, which contains the fix for this vulnerability. Multiple Linux distributions have released security updates including Ubuntu (USN-4361-1), Debian (DSA-4690), and Fedora. For LMTP services, the risk can be partially mitigated as it is typically deployed behind a trusted MTA (Ubuntu Security, Debian Security).

Additional resources


SourceThis report was generated using AI

Related Dovecot vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-27851CRITICAL9.1
  • Dovecot logoDovecot
  • dovecot
NoYesMay 12, 2026
CVE-2026-40016MEDIUM6.5
  • Dovecot logoDovecot
  • dovecot24
NoYesMay 12, 2026
CVE-2026-33603MEDIUM5.3
  • Dovecot logoDovecot
  • dovecot-mysql-debuginfo
NoYesMay 12, 2026
CVE-2026-42006MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot-devel
NoYesMay 12, 2026
CVE-2026-40020MEDIUM4.3
  • Dovecot logoDovecot
  • dovecot22-devel
NoYesMay 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management