MailEnable SMTP Server HELO Command Remote DoS

medium Nessus Plugin ID 21771


The remote SMTP server is susceptible to a denial of service attack.


The remote host is running MailEnable, a commercial mail server for Windows.

According to the version number in its banner, the SMTP server bundled with the installation of MailEnable on the remote host will crash when handling malformed HELO commands. An unauthenticated attacker may be able to leverage this issue to deny service to legitimate users.


Apply the ME-10013 hotfix.

See Also

Plugin Details

Severity: Medium

ID: 21771

File Name: mailenable_smtp_helo_dos.nasl

Version: 1.19

Type: remote

Published: 6/28/2006

Updated: 11/15/2018

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information


Risk Factor: Medium

Score: 4.2


Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: cpe:/a:mailenable:mailenable

Required KB Items: Settings/ParanoidReport

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 6/24/2006

Reference Information

CVE: CVE-2006-3277

BID: 18630