← Vulnerability feed

Vulnerability record · CVE-2020-28019 · published 6 May 2021

CVE-2020-28019: Exim improper initialization in BDAT handling causes stack exhaustion

Exim · Exim

Exim 4 before 4.94.2 mishandles certain getc functions when a client uses BDAT instead of DATA, an improper initialization flaw (CWE-665). The result can be recursion-based stack consumption or other unspecified consequences, making it a remotely reachable availability risk for mail servers.

7.5 CVSS 3.1 High EPSS 62% · top 0.9% CWE-665 · CWE-665
7.5CVSS 3.1 base score, v2 5.0
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated availability impact on a widely deployed mail server plus a very high EPSS percentile justify high priority despite no KEV listing.

What it is

Exim 4 before 4.94.2 mishandles certain getc functions when a client uses BDAT instead of DATA, an improper initialization flaw (CWE-665). The result can be recursion-based stack consumption or other unspecified consequences, making it a remotely reachable availability risk for mail servers.

Impact

An attacker can drive recursion-based stack consumption, degrading or crashing the Exim process and disrupting mail service. The CVSS vector shows only availability impact, with no confidentiality or integrity loss.

Attack surface

Reachable over the network via SMTP by a client issuing BDAT commands; the CVSS vector indicates no authentication and no user interaction are required. The flaw is in the server's handling of the BDAT transfer path rather than the normal DATA path.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is high at 0.61664 (99.13 percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Upgrade Exim to 4.94.2 or later, which contains the fix for this BDAT handling flaw.
  • If immediate upgrade is not possible, restrict or disable BDAT support where the deployment allows it, and limit SMTP exposure to trusted networks.
  • Monitor Exim processes for abnormal memory growth or crashes and restart under supervision to limit availability impact.
  • Apply vendor guidance from the Exim security advisory for CVE-2020-28019 and track any follow-up patches.

Detection

  • Alert on Exim crashes, restarts, or stack-related error messages correlated with SMTP BDAT commands.
  • Log and review SMTP sessions using BDAT, especially from untrusted or unexpected source addresses.
  • Monitor Exim process memory and CPU for abnormal growth patterns that could indicate recursion-based stack consumption.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28019 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed9.8CVE-2018-6789Exim SMTP base64d buffer overflow allows remote code executionExim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the f…KEVEPSS 82%analysed9.8CVE-2010-4344Exim SMTP heap buffer overflow enables remote code executionExim before 4.70 has a heap-based buffer overflow in string_vformat in string.c. A remote SMTP session that sends two MAIL commands plus a large mess…KEVEPSS 72%analysed7.8CVE-2010-4345Exim local privilege escalation via alternate config file command injectionExim 4.72 and earlier lets the exim user account specify an alternate configuration file whose directives can contain arbitrary commands, as shown wi…KEVEPSS 18%analysed9.8CVE-2026-45185Exim use after free vulnerabilityExim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a c…EPSS 0.94%9.8CVE-2026-40685Exim out-of-bounds write vulnerabilityIn Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrus…EPSS 0.58%9.8CVE-2025-67896Exim heap-based buffer overflow vulnerabilityExim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2020-28019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.