
Cloud Vulnerability DB
A community-led vulnerabilities database
In Dovecot before version 2.3.10.1, a security vulnerability was discovered where unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp services. The vulnerability was assigned CVE-2020-10957 and was discovered by Philippe Antoine from Catena Cyber. The issue was reported on March 24, 2020, and fixed on April 2, 2020, with public disclosure on May 18, 2020. The vulnerability affects Dovecot versions 2.3.0 through 2.3.10 (Openwall OSS, Dovecot Security).
The vulnerability is classified as a NULL pointer dereference (CWE-476) with a CVSS v3.1 score of 7.5 (High). The issue occurs when a client sends a NOOP command with an invalid string parameter, particularly when the parameter doesn't start with a double quote. This vulnerability can be triggered by sending commands like NOOP EE"FY to the submission port. The high severity score is due to the attack vector being network-accessible (AV:N), requiring low attack complexity (AC:L), no privileges (PR:N), and no user interaction (UI:N), with impact limited to availability (A:H) (Openwall OSS).
The primary impact of this vulnerability is a denial of service condition. A remote attacker can keep the submission-login service down by repeatedly exploiting this vulnerability. For LMTP service, the risk is considered negligible as it is typically deployed behind a trusted MTA. The vulnerability affects the availability of the service but does not compromise confidentiality or integrity (Openwall OSS).
The vulnerability is highly exploitable as it requires no authentication and can be triggered remotely by sending malformed NOOP commands to the submission port. This makes it particularly dangerous for the submission-login service, which can be targeted without authentication. A proof of concept exists involving sending the command NOOP EE"FY to the submission port (Openwall OSS, PacketStorm).
The primary mitigation is to upgrade to Dovecot version 2.3.10.1 or later, which contains the fix for this vulnerability. Multiple Linux distributions have released security updates including Ubuntu (USN-4361-1), Debian (DSA-4690), and Fedora. For LMTP services, the risk can be partially mitigated as it is typically deployed behind a trusted MTA (Ubuntu Security, Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."