← Vulnerability feed

Vulnerability record · CVE-2020-13951 · published 30 September 2020

CVE-2020-13951: Apache OpenMeetings NetTest web service denial of service

Apache · Openmeetings

The public NetTest web service in Apache OpenMeetings 4.0.0 through 5.0.0 can be abused to conduct a denial of service attack. Because the endpoint is reachable without authentication, any remote attacker can degrade or take down the service, which matters for internet-exposed meeting servers. The record gives no detail on the exact resource exhaustion mechanism or the fix version.

7.5 CVSS 3.1 High EPSS 69% · top 0.7%
7.5CVSS 3.1 base score, v2 5.0
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote denial of service with a 7.5 CVSS score and very high EPSS probability, though no KEV listing or confirmed exploitation.

What it is

The public NetTest web service in Apache OpenMeetings 4.0.0 through 5.0.0 can be abused to conduct a denial of service attack. Because the endpoint is reachable without authentication, any remote attacker can degrade or take down the service, which matters for internet-exposed meeting servers. The record gives no detail on the exact resource exhaustion mechanism or the fix version.

Impact

An attacker can disrupt availability of the OpenMeetings service, denying legitimate users access to meetings and related functionality. No confidentiality or integrity impact is indicated by the CVSS vector.

Attack surface

Reachable over the network through the public NetTest web service; the CVSS vector shows no privileges and no user interaction required. Any host exposing the affected OpenMeetings version is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.70 (99th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are advisory and third-party only, so no confirmed in-the-wild exploitation is documented here.

What to do

  • Upgrade Apache OpenMeetings to a version later than 5.0.0 that contains the fix; the record does not name the fixed release, so confirm with the vendor advisory.
  • Restrict network access to the NetTest web service and other OpenMeetings endpoints to trusted networks or VPN where possible.
  • Place the service behind a reverse proxy or WAF with rate limiting and request size limits to blunt volumetric abuse.
  • Monitor and cap resource consumption (threads, connections, memory) for the OpenMeetings process to limit blast radius.
  • If the NetTest endpoint is not needed, disable or block it at the perimeter.

Detection

  • Alert on abnormal request volume or connection spikes against the NetTest endpoint in web server or proxy logs.
  • Monitor OpenMeetings process CPU, memory and thread counts for sustained saturation or restarts.
  • Watch for repeated requests from single source IPs or unusual user agents hitting the NetTest path.
  • Correlate service unavailability events with concurrent traffic patterns to the OpenMeetings host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13951 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2017-7664Apache openmeetings xml external entity (xxe) vulnerabilityUploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.EPSS 2.3%9.8CVE-2024-54676Apache OpenMeetings OpenJPA deserialization of untrusted dataApache OpenMeetings versions from 2.1.0 before 8.0.0 ship default clustering instructions that omit OpenJPA serialization class white/black lists, al…EPSS 65%analysed9.8CVE-2023-28326Apache openmeetings missing authentication for critical function vulnerabilityVendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privile…EPSS 1.3%9.8CVE-2016-8736Apache openmeetings deserialization of untrusted data vulnerabilityApache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.EPSS 4.8%9.8CVE-2017-7673Apache openmeetings improper restriction of authentication attempts vulnerabilityApache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms …EPSS 1.6%8.8CVE-2017-7666Apache openmeetings cross-site scripting vulnerabilityApache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.EPSS 0.80%8.8CVE-2017-7681Apache openmeetings sql injection vulnerabilityApache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the …EPSS 1.3%8.2CVE-2017-7682Apache openmeetings vulnerabilityApache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2020-13951), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.