HIGH🇵🇱 Wersja polska

CVE-2014-3451

CVSS 7.5v3.0pub. 2017-08-18upd. 2026-05-13

OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Igniterealtime Openfire

    APP
    Igniterealtime
    ≤ 3.9.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-25421CRITICAL9.8PL ✓same product

Privilege escalation w Ignite Realtime Openfire przez komponent ROOM_CACHE

CVE-2021-45967CRITICAL9.8PL ✓same product

Path traversal w Pascom Cloud Phone System przez błąd konfiguracji NGINX/Tomcat

CVE-2019-18394CRITICAL9.8PL ✓same product

SSRF w Ignite Realtime Openfire — dowolne żądania HTTP GET

CVE-2023-32315HIGH8.6⚠ KEVsame product

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a...

CVE-2024-25420HIGH7.2same product

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admi...