Opengear produces a focused line of console servers and remote-access appliances designed for out-of-band management and secure access to networked infrastructure, with its disclosed vulnerabilities clustering around authentication and input-validation weaknesses affecting products such as the ACM5000, CM4000, and IM4000/4200 series. These weakness classes—improper authentication mechanisms and cross-site scripting in web interfaces—reflect the management and credential-handling attack surface inherent to appliances positioned for administrative access. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opengear over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3997HIGH Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipment, via unspecified vectors. | Nov 9, 2011 | 7.5 | 23 | NO | NO |
CVE-2019-14456MEDIUM Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a s | Jul 31, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opengear.
Media articles that mention a CVE ID that affects a product developed by Opengear — matched by CVE ID, not by vendor name.