Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-25930

16
FAUCET Score

CVE-2021-25930 is a Cross-Site Request Forgery (CSRF) vulnerability affecting OpenNMS Horizon (versions 1.0-stable to 27.1.0-1) and OpenNMS Meridian (various versions from 2015.1.0-1 to 2020.1.6-1). The flaw stems from a lack of CSRF protection and insufficient validation when renaming users, allowing an attacker to overwrite a renamed user's privileges with those of the old user, effectively deleting the old user from the list. Rated Medium severity (CVSS 4.3), this vulnerability requires user interaction (UI:R) but has low impact (I:L) on integrity, with no confidentiality or availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0, < 27.1.1CPE matchmatch criteria
cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*
>= 2015.1.0, < 2019.1.19CPE matchmatch criteria
cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*
>= 2020.1.0, < 2020.1.7CPE matchmatch criteria
cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 50th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.opennms:opennmsFixed in: 27.1.1
mavenpatch availablevia ghsa
Product: org.opennms:opennms-configFixed in: 27.1.1

Vendor Advisories (1)

mavenGHSA-p63h-7hw8-5cw4medium

Cross-Site Request Forgery in OpenNMS Horizon

May 25, 2021

References

github.com / OpenNMS/opennms/commit/607151ea8f90212a3fb37c977fa57c7d58d26a84
PatchThird Party Advisory
github.com / OpenNMS/opennms/commit/eb08b5ed4c5548f3e941a1f0d0363ae4439fa98c
PatchThird Party Advisory
whitesourcesoftware.com / vulnerability-database/CVE-2021-25930
ExploitThird Party Advisory