Vulnerability record · CVE-2005-2223 · published 12 July 2005
CVE-2005-2223: MailEnable SMTP service crash during authentication
Mailenable · Mailenable Professional
MailEnable Standard before 1.9 and Professional before 1.6 contain an unspecified vulnerability in the SMTP service that lets a remote attacker crash the service during authentication. The flaw is unauthenticated and network-reachable, so it can interrupt mail service for any exposed server. The record gives no root-cause detail beyond the authentication phase, so the exact trigger is unknown.
Description
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityUnauthenticated remote denial of service with high EPSS but only partial availability impact and no evidence of active exploitation or KEV listing.
What it is
MailEnable Standard before 1.9 and Professional before 1.6 contain an unspecified vulnerability in the SMTP service that lets a remote attacker crash the service during authentication. The flaw is unauthenticated and network-reachable, so it can interrupt mail service for any exposed server. The record gives no root-cause detail beyond the authentication phase, so the exact trigger is unknown.
Impact
An attacker can cause a denial of service by crashing the SMTP service, disrupting mail delivery and potentially other dependent services on the host. No confidentiality or integrity impact is indicated by the CVSS vector.
Attack surface
Reachable over the network via the SMTP service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The crash occurs during the authentication exchange.
Exploitation
Not listed in CISA KEV and no public exploit is referenced, but EPSS is 0.50805 (98.9th percentile), indicating a high predicted likelihood of exploitation activity. Reference tags only indicate a patch link, not exploit code.
What to do
- Upgrade MailEnable Standard to 1.9 or later and Professional to 1.6 or later, per the vendor patch reference.
- Restrict SMTP access to trusted networks and required mail relays using firewall rules.
- Disable or tightly limit SMTP authentication exposure to the internet where operationally possible.
- Monitor the SMTP service for unexpected restarts and configure automatic recovery or alerting.
- Review vendor history pages for the exact fixed build before deploying.
Detection
- Alert on SMTP service crash, restart or unexpected process termination events on MailEnable hosts.
- Monitor authentication-phase SMTP sessions for repeated failures or malformed AUTH commands from single sources.
- Baseline normal SMTP authentication traffic and flag anomalous connection patterns or volumes.
- Correlate mail service downtime with inbound SMTP connection logs to identify a triggering source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2223 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.