Vulnerability record · CVE-2007-1675 · published 28 March 2007
CVE-2007-1675: IBM Lotus Domino IMAP CRAM-MD5 buffer overflow via long username
Ibm · Lotus Domino
The CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 contains a buffer overflow. A remote attacker can trigger it by sending an overly long username during authentication. The flaw matters because it can crash or destabilize the IMAP service, and the CVSS 2.0 vector suggests possible full confidentiality, integrity and availability impact.
Description
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated buffer overflow with a CVSS 2.0 score of 10 and very high EPSS, though only denial of service is explicitly described and no known exploitation is listed.
What it is
The CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 contains a buffer overflow. A remote attacker can trigger it by sending an overly long username during authentication. The flaw matters because it can crash or destabilize the IMAP service, and the CVSS 2.0 vector suggests possible full confidentiality, integrity and availability impact.
Impact
An attacker can cause a denial of service against the IMAP service. The CVSS 2.0 vector (C:C/I:C/A:C) indicates potential complete loss of confidentiality, integrity and availability, though the description only confirms denial of service.
Attack surface
Reachable over the network through the IMAP service, specifically the CRAM-MD5 authentication path. No authentication is required per the CVSS vector (Au:N), and no user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.6122, 99.1st percentile), and references include vendor advisory and patch links but no public exploit tag.
What to do
- Apply the IBM patch referenced in the vendor advisory (swg21257028) or upgrade to Lotus Domino 6.5.6 / 7.0.2 FP1 or later.
- If patching is not immediately possible, disable or restrict the CRAM-MD5 authentication mechanism on the IMAP service.
- Limit network access to the IMAP service (nimap.exe) to trusted hosts or internal networks.
- Monitor IBM advisories and securityfocus BID 23173 for updated guidance.
Detection
- Inspect IMAP authentication logs for unusually long usernames or malformed CRAM-MD5 authentication attempts.
- Monitor for crashes or restarts of nimap.exe on Lotus Domino servers.
- Use network IDS signatures for oversized IMAP AUTHENTICATE CRAM-MD5 commands if available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1675 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1675), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.