cbcvebase.
CVE-2011-2166
published 2011-05-24

CVE-2011-2166: script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass…

PriorityP428medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.01%
78.8th percentile
script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandovecot< dovecot 1:2.0.13-1 (bookworm)dovecot 1:2.0.13-1 (bookworm)
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot
dovecotdovecot>= 0 < 1:2.0.13-11:2.0.13-1
dovecotdovecot>= 0 < 1:2.0.13-11:2.0.13-1
dovecotdovecot>= 0 < 1:2.0.13-11:2.0.13-1
dovecotdovecot>= 0 < 1:2.0.13-11:2.0.13-1

CVSS provenance

nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.