CVE-2007-6598 describes a vulnerability in Dovecot versions prior to 1.0.10, where a misconfigured LDAP+auth cache, particularly when using %variables, could allow remote authenticated users to log in as a different user sharing the same password. This vulnerability carries a CVSS score of 6.8, indicating a medium severity with network access, medium attack complexity, and potential for partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness and limited exploitation interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.9CPE matchmatch criteria | cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.