The OpenNMS Group maintains a focused network management and monitoring platform, anchored around its flagship Meridian and Horizon products, that serves as a central collection and visibility layer for enterprises managing distributed infrastructure. The vendor's vulnerability profile concentrates on application-layer input handling and serialization issues, with recurring weakness classes including cross-site scripting, improper input validation, CSRF, and deserialization of untrusted data that are typical of web-based management consoles handling complex, user-supplied configuration. The platform's role as a network intelligence hub means that vulnerabilities affecting it can provide pivots to broader infrastructure; a moderate tendency toward public exploit availability reflects the appeal of management-plane access. Defenders should treat OpenNMS updates as relevant to network visibility and control infrastructure and maintain access restrictions appropriate to the platform's administrative functions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by The OpenNMS Group over time
Of all the CVEs published by The OpenNMS Group as a CNA, 87.5% affect products that The OpenNMS Group develops as a vendor.
Of all the CVEs published that affect products developed by The OpenNMS Group, 46.7% are self-published by The OpenNMS Group as a CNA.
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0872HIGH The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solutio | Aug 14, 2023 | 8.0 | 37 | NO | YES |
CVE-2023-40315HIGH In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_ | Aug 17, 2023 | 8.0 | 33 | NO | YES |
CVE-2021-3396HIGH OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, whic | Feb 17, 2021 | 8.8 | 27 | NO | NO |
CVE-2015-7856HIGH OpenNMS has a default password of rtc for the rtc account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials. | Oct 16, 2015 | 10.0 | 25 | NO | NO |
CVE-2023-40313HIGH A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code exe | Aug 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-25931HIGH In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridia | May 20, 2021 | 8.8 | 24 | NO | NO |
CVE-2020-1652CRITICAL OpenNMS is accessible via port 9443 | Jul 17, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-12760HIGH An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deseriali | May 11, 2020 | 8.8 | 23 | NO | NO |
CVE-2023-40612HIGH In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection at | Aug 23, 2023 | 8.0 | 21 | NO | NO |
CVE-2023-0871MEDIUM XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which ca | Aug 11, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by The OpenNMS Group.
Media articles that mention a CVE ID that affects a product developed by The OpenNMS Group — matched by CVE ID, not by vendor name.