VulnerabilityModified
CVE-2009-1596
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a…
MEDIUM 6.5EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- igniterealtime/openfire
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/34984Broken Link, Vendor Advisory
- http://www.igniterealtime.org/community/message/190280Exploit, Issue Tracking, Patch, Vendor Advisory
- http://www.igniterealtime.org/issues/browse/JM-1532Patch, Permissions Required, Vendor Advisory
- http://www.osvdb.org/54189Broken Link
- http://www.securityfocus.com/bid/34804Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50291Third Party Advisory, VDB Entry
- http://secunia.com/advisories/34984Broken Link, Vendor Advisory
- http://www.igniterealtime.org/community/message/190280Exploit, Issue Tracking, Patch, Vendor Advisory
- http://www.igniterealtime.org/issues/browse/JM-1532Patch, Permissions Required, Vendor Advisory
- http://www.osvdb.org/54189Broken Link
- http://www.securityfocus.com/bid/34804Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50291Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.