CVE-2026-33603 - CERT CVE
ID CVE-2026-33603
Sažetak Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.
Reference
CVSS
Base: 6.8
Impact: 5.2
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH NONE
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Zadnje važnije ažuriranje 18-05-2026 - 17:35
Objavljeno 12-05-2026 - 14:17