CVE-2023-0870 describes a Cross-Site Request Forgery (CSRF) vulnerability affecting OpenNMS Meridian and Horizon, allowing manipulation of forms. This medium-severity flaw (CVSS 6.7) requires local network access and user interaction, potentially leading to high impact on confidentiality and integrity. While no public exploits, Metasploit modules, or community discussions are reported, organizations should upgrade to Meridian 2023.1.1 or Horizon 31.0.6 or newer to mitigate the risk. It's important to note that these products are typically deployed in private networks, limiting direct internet exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 31.0.6CPE matchmatch criteria | cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:* | ||
>= 2020.1.0, < 2020.1.33CPE matchmatch criteria | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* | ||
>= 2021.1.0, < 2021.1.25CPE matchmatch criteria | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* | ||
>= 2022.1.0, < 2022.1.14CPE matchmatch criteria | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* | ||
2023.1.0CPE matchmatch criteria | cpe:2.3:a:opennms:meridian:2023.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.