Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Alto CVE-2026-103649 Multiple Vendors

Vulnerabilidad de denegación de servicio en hMailServer 6.3.0-6.3.5 en Linux por falta de timeouts

Vulnerabilidad · Publicado 08/10/2026

7.5
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

Progressive Robot hMailServer versiones 6.3.0 a 6.3.5 en Linux presenta un defecto alta donde falta configuración de timeouts en conexiones de red, permitiendo a atacantes remotos bloquear threads del servidor e interrumpir la entrega de correo saliente. Este problema afecta directamente a servidores de correo empresariales en México y Latinoamérica que utilizan estas versiones en infraestructura Linux, causando degradación severa del servicio de comunicaciones.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

Missing network timeouts in the Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 allow a remote attacker to hold server threads indefinitely and so stop outbound mail delivery (denial of service). The server set its socket timeouts in the form Windows takes, which Linux refuses, and its HTTPS clients read without a deadline, so a peer that accepts a connection and then sends nothing held the waiting thread for as long as the connection stayed open. The MTA-STS policy fetch, enabled by default, is made during outbound delivery to mta-sts.<recipient domain>, so anyone who can make the server deliver mail to a domain they control - for example as the envelope sender of a message that bounces - can hold delivery threads until outbound delivery stops. The same flaw affects the DANE TLSA query, the OAuth2 token request, the ACME client, and the ManageSieve and metrics listeners, which a silent client stops from serving anyone else. Windows builds are not affected.

Puntuación CVSS

Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Debilidades (CWE)

CWE-1088

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Identificar sistemas con hMailServer 6.3.0-6.3.5 en entornos Linux;
  • Aplicar parche oficial del fabricante Progressive Robot inmediatamente;
  • Implementar control de acceso de red para limitar conexiones a puertos SMTP/HTTPS;
  • Monitorear logs de servidor para intentos de conexión anormales;
  • Validar en ambiente de prueba antes de producción;
  • Consultar NIST NVD para confirmar disponibilidad de actualizaciones
Esta alerta fue generada automáticamente a partir del NVD del NIST.