First published: Fri Aug 18 2017(Updated: )
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Igniterealtime Openfire | <=3.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3451 has a medium severity level due to the potential for spoofing attacks.
To fix CVE-2014-3451, upgrade OpenFire to version 3.10 or later to disable acceptance of self-signed certificates.
CVE-2014-3451 affects OpenFire versions prior to 3.10, specifically versions up to and including 3.9.3.
CVE-2014-3451 can be exploited to perform spoofing attacks through the acceptance of self-signed certificates.
A workaround for CVE-2014-3451 is to configure OpenFire to require valid certificates from trusted certificate authorities.