Vulnerability record · CVE-2006-6423 · published 12 December 2006
CVE-2006-6423: MailEnable IMAP Service Pre-Auth Stack Buffer Overflow
Mailenable · Mailenable Enterprise
MailEnable Professional and Enterprise IMAP service contains a stack-based buffer overflow reachable before authentication. A remote attacker can send a crafted command with an oversized parameter to corrupt the stack and potentially execute arbitrary code. The flaw affects multiple 1.x and 2.x branches and was fixed by the ME-10025 hotfix.
Description
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a pre-authentication command followed by a crafted parameter and a long string, as addressed by the ME-10025 hotfix.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityPre-authentication remote code execution with a CVSS 2.0 score of 10 and very high EPSS probability makes this an urgent patch target despite no KEV listing.
What it is
MailEnable Professional and Enterprise IMAP service contains a stack-based buffer overflow reachable before authentication. A remote attacker can send a crafted command with an oversized parameter to corrupt the stack and potentially execute arbitrary code. The flaw affects multiple 1.x and 2.x branches and was fixed by the ME-10025 hotfix.
Impact
Successful exploitation can give a remote unauthenticated attacker arbitrary code execution in the context of the IMAP service, leading to full compromise of the mail server. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
The IMAP service is network-reachable and the overflow is triggered by a pre-authentication command followed by a crafted parameter and long string, so no credentials or user interaction are required. Any host exposing the MailEnable IMAP listener is in scope.
Exploitation
The record is not listed in CISA KEV and no ransomware associations are documented. EPSS is high at roughly 0.707 (99.4th percentile), and references include vendor and Secunia advisories tagged Patch, but no public exploit code is confirmed in the supplied data.
What to do
- Apply the vendor ME-10025 hotfix or upgrade to a fixed MailEnable build immediately.
- Restrict network access to the IMAP service to trusted hosts or VPN where possible.
- Place the mail server behind filtering that rejects malformed or oversized IMAP commands.
- Monitor vendor advisories for the affected 1.x and 2.x branches and confirm the installed build is patched.
- Segment the mail server so a compromise cannot pivot freely into other internal systems.
Detection
- Inspect IMAP service logs for pre-authentication commands with unusually long parameters or malformed syntax.
- Alert on crashes or restarts of the MailEnable IMAP service, which may indicate attempted exploitation.
- Use network IDS signatures for oversized IMAP command parameters against the MailEnable listener.
- Correlate inbound IMAP connections from unexpected external sources with service fault events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-6423 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-6423), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.