CVE-2011-3372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
24/12/2011
Last modified:
11/04/2025

Description

imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO USER command without sending an additional AUTHINFO PASS command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyrus:imapd:*:*:*:*:*:*:*:* 2.4.11 (including)