CVE-2023-26432Uncontrolled Resource Consumption in Appsuite Backend

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 67.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 20

Description

When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable length/size. No publicly available exploits are known.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5ox_software_gmbh/ox_app_suite7.10.6-rev39+1

🔴Vulnerability Details

2
CVEList
CVE-2023-26432: When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes2023-06-20
GHSA
GHSA-9628-xx9p-xjqj: When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes2023-06-20
CVE-2023-26432 — Uncontrolled Resource Consumption | cvebase