OX Dovecot OTP Authentication Replay Attack Vulnerability

Vulnerability

A replay attack vulnerability has been identified in OX Dovecot authentication using One-Time Passwords (OTP). This issue arises under specific conditions: when the authentication cache is enabled and the username is modified in the password database. In such cases, OTP credentials can be cached, allowing the same OTP response to be reused for authentication. An attacker who observes an OTP exchange can exploit this vulnerability to log in as the user. This vulnerability affects OX Dovecot Pro versions 2.3.0, 3.0.2, 3.1.0, and OX Dovecot CE versions 2.4.0, 2.4.1, and 2.4.3.

Impact

Exploitation of this vulnerability allows an attacker to bypass OTP authentication, logging in as the user whose OTP was observed.

Remediation

Users should switch to a secure connection and, if possible, use the SCRAM protocol for authentication. For those on OX Dovecot Pro 2.3.0, the authentication cache can be disabled or the application can be upgraded to a fixed version.

Added: Mar 27, 2026, 9:22 AM
Updated: Mar 27, 2026, 9:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.6
remediation
0.0
relevance
4.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.