Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

The OpenNMS Group

First CVE: Feb 9, 2009Active for: 17 yearsTotal CVEs: 30
26.7
VTI Score
Low

The OpenNMS Group maintains a focused network management and monitoring platform, anchored around its flagship Meridian and Horizon products, that serves as a central collection and visibility layer for enterprises managing distributed infrastructure. The vendor's vulnerability profile concentrates on application-layer input handling and serialization issues, with recurring weakness classes including cross-site scripting, improper input validation, CSRF, and deserialization of untrusted data that are typical of web-based management consoles handling complex, user-supplied configuration. The platform's role as a network intelligence hub means that vulnerabilities affecting it can provide pivots to broader infrastructure; a moderate tendency toward public exploit availability reflects the appeal of management-plane access. Defenders should treat OpenNMS updates as relevant to network visibility and control infrastructure and maintain access restrictions appropriate to the platform's administrative functions; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by The OpenNMS Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2009
17 years ago
Most Recent CVE
Nov 16, 2023
982 days ago

Self-Reporting Analysis

Of all the CVEs published by The OpenNMS Group as a CNA, 87.5% affect products that The OpenNMS Group develops as a vendor.

87.5%
12.5%
Self-reported: 14 (87.5%)
Third-party: 2 (12.5%)

Of all the CVEs published that affect products developed by The OpenNMS Group, 46.7% are self-published by The OpenNMS Group as a CNA.

46.7%
53.3%
Self-published: 14 (46.7%)
Other CNAs: 16 (53.3%)

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0872HIGH
The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solutio
Aug 14, 20238.037NOYES
CVE-2023-40315HIGH
In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_
Aug 17, 20238.033NOYES
CVE-2021-3396HIGH
OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, whic
Feb 17, 20218.827NONO
CVE-2015-7856HIGH
OpenNMS has a default password of rtc for the rtc account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.
Oct 16, 201510.025NONO
CVE-2023-40313HIGH
A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code exe
Aug 17, 20238.824NONO
CVE-2021-25931HIGH
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridia
May 20, 20218.824NONO
CVE-2020-1652CRITICAL
OpenNMS is accessible via port 9443
Jul 17, 20209.824NONO
CVE-2020-12760HIGH
An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deseriali
May 11, 20208.823NONO
CVE-2023-40612HIGH
In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection at
Aug 23, 20238.021NONO
CVE-2023-0871MEDIUM
XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which ca
Aug 11, 20236.121NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
67%
30%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (63.3%)
Unknown3 (10.0%)
Physical0 (0.0%)
Adjacent Network8 (26.7%)
Attack Complexity
Low27 (90.0%)
High0 (0.0%)
Unknown3 (10.0%)
User Interaction
None10 (33.3%)
Unknown3 (10.0%)
Required17 (56.7%)
Privileges Required
Low12 (40.0%)
High2 (6.7%)
None13 (43.3%)
Unknown3 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
6.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by The OpenNMS Group.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by The OpenNMS Group — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For The OpenNMS Group's Products

View all 5 CNAs →

Top CWEs