Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11499

25
FAUCET Score

CVE-2019-11499 describes a denial-of-service vulnerability affecting Dovecot IMAP Server versions 2.3.3 through 2.3.5.2, as well as various Dovecot packages for Fedora and openSUSE. An unauthenticated attacker can crash the server by attempting an AUTH PLAIN authentication over a TLS-secured channel with an unacceptable message. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity leading to high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.3.3, <= 2.3.5.2CPE matchmatch criteria
cpe:2.3:a:dovecot:dovecot:*:*:*:*:*:*:*:*
29CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
15.0CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
15.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.53%
Probability of exploitation in next 30 days
EPSS Percentile
83.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0253 is in the 70th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

denopatch availablevia llm_extracted
View patch
drupalpatch availablevia llm_extracted
View patch
freeswitchpatch availablevia llm_extracted
View patch
synologypatch availablevia llm_extracted
Fixed in: null
View patch
boschvendor investigatingvia llm_extracted
View patch
broadcomvendor investigatingvia llm_extracted
View patch
ubiquitivendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

redhatCVE-2019-11499Moderate

dovecot: unacceptable authentication message in AUTH PLAIN over TLS leads to crash and possible DoS

Apr 30, 2019
drupalllm-drupal-d326271ca4dfc53e

Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent

Apr 30, 2019
ubiquitillm-ubiquiti-ef5d529ea650e0d6

Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent

Apr 30, 2019
synologyllm-synology-f4b7cc298f1749fa

Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent

Apr 30, 2019
denollm-deno-1c44aa40f3cc54ad

Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent

Apr 30, 2019
broadcomllm-broadcom-ccc9ca583a424f6b

CVE-2019-11499: Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent

Apr 30, 2019
freeswitchllm-freeswitch-b001820676eaacb5

Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent

Apr 30, 2019
boschllm-bosch-7fbfc2435841f197

CVE-2019-11499: Submission-login crashes when authentication is started over TLS secured channel and invalid authentication message is sent

Apr 30, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-10/msg00024.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-10/msg00026.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4XLI55NGRDTGMVOPYFCPPFNPA5VKYSSY
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QHFZ5OWRIZGIWZJ5PTNVWWZNLLNH4XYS
dovecot.org / download.html
Product
dovecot.org / security.html
Vendor Advisory