Vulnerability record · CVE-2020-28019 · published 6 May 2021
CVE-2020-28019: Exim improper initialization in BDAT handling causes stack exhaustion
Exim · Exim
Exim 4 before 4.94.2 mishandles certain getc functions when a client uses BDAT instead of DATA, an improper initialization flaw (CWE-665). The result can be recursion-based stack consumption or other unspecified consequences, making it a remotely reachable availability risk for mail servers.
Description
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated availability impact on a widely deployed mail server plus a very high EPSS percentile justify high priority despite no KEV listing.
What it is
Exim 4 before 4.94.2 mishandles certain getc functions when a client uses BDAT instead of DATA, an improper initialization flaw (CWE-665). The result can be recursion-based stack consumption or other unspecified consequences, making it a remotely reachable availability risk for mail servers.
Impact
An attacker can drive recursion-based stack consumption, degrading or crashing the Exim process and disrupting mail service. The CVSS vector shows only availability impact, with no confidentiality or integrity loss.
Attack surface
Reachable over the network via SMTP by a client issuing BDAT commands; the CVSS vector indicates no authentication and no user interaction are required. The flaw is in the server's handling of the BDAT transfer path rather than the normal DATA path.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is high at 0.61664 (99.13 percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Upgrade Exim to 4.94.2 or later, which contains the fix for this BDAT handling flaw.
- If immediate upgrade is not possible, restrict or disable BDAT support where the deployment allows it, and limit SMTP exposure to trusted networks.
- Monitor Exim processes for abnormal memory growth or crashes and restart under supervision to limit availability impact.
- Apply vendor guidance from the Exim security advisory for CVE-2020-28019 and track any follow-up patches.
Detection
- Alert on Exim crashes, restarts, or stack-related error messages correlated with SMTP BDAT commands.
- Log and review SMTP sessions using BDAT, especially from untrusted or unexpected source addresses.
- Monitor Exim process memory and CPU for abnormal growth patterns that could indicate recursion-based stack consumption.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exim.org/static/doc/security/CVE-2020-qualys/CVE-2020-28019-BDATA.txt | Vendor Advisory |
| https://www.exim.org/static/doc/security/CVE-2020-qualys/CVE-2020-28019-BDATA.txt | Vendor Advisory |
Track CVE-2020-28019 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.