Vulnerability record · CVE-2016-8652 · published 17 February 2017
CVE-2016-8652: Dovecot auth component crash via aborted authentication without username
Dovecot · Dovecot
Dovecot before 2.2.27, when auth-policy is configured, fails to validate input in the auth component: a remote attacker can abort an authentication attempt without setting a username, crashing the service. The flaw matters because it lets an unauthenticated remote party disrupt mail authentication availability on affected configurations.
Description
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityRemote unauthenticated crash is limited to auth-policy deployments and causes only availability loss, but the high EPSS score warrants timely patching.
What it is
Dovecot before 2.2.27, when auth-policy is configured, fails to validate input in the auth component: a remote attacker can abort an authentication attempt without setting a username, crashing the service. The flaw matters because it lets an unauthenticated remote party disrupt mail authentication availability on affected configurations.
Impact
An attacker can cause a denial of service by crashing the Dovecot auth process, interrupting authentication for legitimate users. No data confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable remotely over the network against the Dovecot auth service, with no authentication or user interaction required per the CVSS vector (AV:N/PR:N/UI:N). It only applies when auth-policy is configured, which limits exposure to those deployments.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record. EPSS is high (0.48197, ~98.8th percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Upgrade Dovecot to 2.2.27 or later, which contains the fix.
- If immediate upgrade is not possible, disable or avoid auth-policy configuration where it is not required.
- Restrict network access to the Dovecot auth service to trusted clients only.
- Monitor vendor release notes and mailing list advisories for any follow-up fixes.
Detection
- Alert on Dovecot auth process crashes or unexpected restarts in service and system logs.
- Monitor for repeated aborted authentication attempts lacking a username in auth logs.
- Track availability gaps in mail authentication and correlate with auth-policy configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://dovecot.org/pipermail/dovecot-news/2016-December/000333.html | Release NotesVendor Advisory |
| http://www.openwall.com/lists/oss-security/2016/12/02/4 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2016/12/05/12 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/94639 | Third Party AdvisoryVDB Entry |
| http://dovecot.org/pipermail/dovecot-news/2016-December/000333.html | Release NotesVendor Advisory |
| http://www.openwall.com/lists/oss-security/2016/12/02/4 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2016/12/05/12 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/94639 | Third Party AdvisoryVDB Entry |
Track CVE-2016-8652 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8652), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.