CVE-2023-26432: Medium severity open-xchange app suite backend vulnerability
When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable length/size. No publicly available exploits are known.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26432?
CVE-2023-26432 is a vulnerability that allows an attacker to trigger requests that lead to excessive resource usage and service unavailability in Open-xchange Appsuite Backend.
How does CVE-2023-26432 affect Open-xchange Appsuite Backend?
CVE-2023-26432 affects Open-xchange Appsuite Backend versions up to 7.10.6 and versions 8.0.0 to 8.11.0.
What is the severity of CVE-2023-26432?
The severity of CVE-2023-26432 is medium, with a severity value of 4.3.
How can an attacker exploit CVE-2023-26432?
An attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and service unavailability.
How can I mitigate the vulnerability CVE-2023-26432?
To mitigate CVE-2023-26432, it is recommended to update Open-xchange Appsuite Backend to a version that includes the necessary fix.