Openfire 3.10 < 4.6.8 / 4.7 < 4.7.5 Authentication Bypass

high Nessus Plugin ID 177741

Version 1.5

Sep 11, 2023, 4:16 PM

  • Exploit attributes ("Exploited by malware" set to "True")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C")

Plugin Feed: 202309111616

Version 1.4

Aug 25, 2023, 12:02 AM

  • CISA reference

Plugin Feed: 202308250002

Version 1.3

Jul 19, 2023, 2:11 PM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")
  • Exploit attributes ("Exploit framework metasploit" set to "True")

Plugin Feed: 202307191411

Version 1.2

Jul 6, 2023, 2:13 PM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:POC/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:P/RL:O/RC:C")
  • Exploit attributes ("Exploit available" set to "True". "Exploitability ease" set to "Exploits are available")

Plugin Feed: 202307061413

Version 1.1

Jun 30, 2023, 12:02 PM

  • IAVM reference
  • STIG Severity (set to "I")

Plugin Feed: 202306301202

Version 1.0

Jun 29, 2023, 6:02 PM

  • New

Plugin Feed: 202306291802

* Changelogs are generally available for changes made after Nov 1, 2022