CVE-2023-40612 is an XML External Entity (XXE) injection vulnerability affecting OpenNMS Horizon versions prior to 32.0.2 and OpenNMS Meridian. An authenticated attacker with ROLE_FILESYSTEM_EDITOR privileges on an internal network can exploit this to achieve high confidentiality, integrity, and availability impacts. With a CVSS score of 8.0 (High), this vulnerability has no known public exploits, Metasploit modules, or Nuclei templates, and shows no active exploitation or significant community discussion. Organizations are advised to upgrade to Horizon 32.0.2+ or Meridian 2023.1.5+ to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 31.0.8, < 32.0.2CPE matchmatch criteria | cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:* | ||
>= 2023.0.0, < 2023.1.5CPE matchmatch criteria | cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.