CVE-2025-59032 is a high-severity vulnerability affecting the ManageSieve service, where a specially crafted AUTHENTICATE command using a literal as a SASL initial response can cause the service to crash. Rated with a CVSS score of 7.5, this network-exploitable flaw has low attack complexity and requires no privileges or user interaction, leading to a high impact on service availability through repeated denial-of-service attacks. There are currently no known public exploits, exploit code, or evidence of active exploitation, and only minimal community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.3CPE matchmatch criteria | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* | ||
< 3.1.3CPE matchmatch criteria | cpe:2.3:a:open-xchange:dovecot:*:*:*:*:pro:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.