CVE-2014-3430: Dovecot

Medium severity, CVSS 5.0. EPSS: 3.3% chance of exploitation in the next 30 days.

Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.

Affected products

  • Dovecot Dovecot: version 1.1 only; version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.1.3 only; version 1.1.4 only; …

Published 2014-05-14. Last modified 2026-06-17.