Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-30550

29
FAUCET Score

CVE-2022-30550 is a privilege escalation vulnerability affecting Dovecot versions 2.2 and 2.3 prior to 2.3.20. It arises when multiple passdb configurations share the same driver and args, leading to incorrect application of username_filter and mechanism settings. This flaw carries a CVSS score of 8.8 (High), indicating a network-exploitable vulnerability with low attack complexity that can result in high impact to confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.3, < 2.4.0CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
2.2CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:2.2:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.07%
Probability of exploitation in next 30 days
EPSS Percentile
79.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0207 is in the 78th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

denopatch availablevia llm_extracted
View patch
drupalpatch availablevia llm_extracted
View patch
freeswitchpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 19201-16823Fixed in: 2.3.20-1
microsoftpatch availablevia msrc
Product: cbl2 dovecot 2.3.20-1 on CBL Mariner 2.0Fixed in: 2.3.20-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dovecot-1:2.3.16-3.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dovecot-1:2.3.16-7.el9
View patch
synologypatch availablevia llm_extracted
Fixed in: null
View patch
boschvendor investigatingvia llm_extracted
View patch
broadcomvendor investigatingvia llm_extracted
View patch
ubiquitivendor investigatingvia llm_extracted
View patch

Vendor Advisories (9)

microsoft2022-Jul/CVE-2022-30550Important

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation in certain configurations. The documentation does not advise against the use of passdb definitions that have the same driver and args settings. One such configuration would be where an administrator wishes to use the same PAM configuration or passwd file for both normal and master users but use the username_filter setting to restrict which of the users is able to be a master user.

Jul 12, 2022
redhatCVE-2022-30550Moderate

dovecot: Privilege escalation when similar master and non-master passdbs are used

Jul 6, 2022
drupalllm-drupal-4989408ae57a2c7a

Privilege escalation possible in dovecot when similar master and non-master passdbs are used

Jul 6, 2022
ubiquitillm-ubiquiti-1e5c31ed94dc9f16

Privilege escalation possible in dovecot when similar master and non-master passdbs are used

Jul 6, 2022
synologyllm-synology-799993930eef4c27

Privilege escalation possible in dovecot when similar master and non-master passdbs are used

Jul 6, 2022
denollm-deno-b5305ae16f54b77a

Privilege escalation possible in dovecot when similar master and non-master passdbs are used

Jul 6, 2022
broadcomllm-broadcom-79658dc495caa055

CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used

Jul 6, 2022
freeswitchllm-freeswitch-71d5f50909874b2f

Privilege escalation possible in dovecot when similar master and non-master passdbs are used

Jul 6, 2022
boschllm-bosch-21f9a1a39da10a20

CVE-2022-30550: Privilege escalation possible in dovecot when similar master and non-master passdbs are used

Jul 6, 2022

References

dovecot.org / security
Vendor Advisory
lists.debian.org / debian-lts-announce/2022/09/msg00032.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202310-19
Third Party Advisory
dovecot.org / download
Product
openwall.com / lists/oss-security/2022/07/08/1
Mailing ListPatchThird Party Advisory