August 24, 2023 · Applied Cybernetics Group
CVE-2023-32315 — Ignite Realtime Openfire
Ignite Realtime Openfire Path Traversal Vulnerability
- Added to KEV
2023-08-24- Federal due date
2023-09-14- Vendor
- Ignite Realtime
- Product
- Openfire
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-32315
CISA short description
Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.