Vulnerability record · CVE-2020-13951 · published 30 September 2020
CVE-2020-13951: Apache OpenMeetings NetTest web service denial of service
Apache · Openmeetings
The public NetTest web service in Apache OpenMeetings 4.0.0 through 5.0.0 can be abused to conduct a denial of service attack. Because the endpoint is reachable without authentication, any remote attacker can degrade or take down the service, which matters for internet-exposed meeting servers. The record gives no detail on the exact resource exhaustion mechanism or the fix version.
Description
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote denial of service with a 7.5 CVSS score and very high EPSS probability, though no KEV listing or confirmed exploitation.
What it is
The public NetTest web service in Apache OpenMeetings 4.0.0 through 5.0.0 can be abused to conduct a denial of service attack. Because the endpoint is reachable without authentication, any remote attacker can degrade or take down the service, which matters for internet-exposed meeting servers. The record gives no detail on the exact resource exhaustion mechanism or the fix version.
Impact
An attacker can disrupt availability of the OpenMeetings service, denying legitimate users access to meetings and related functionality. No confidentiality or integrity impact is indicated by the CVSS vector.
Attack surface
Reachable over the network through the public NetTest web service; the CVSS vector shows no privileges and no user interaction required. Any host exposing the affected OpenMeetings version is a candidate target.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.70 (99th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are advisory and third-party only, so no confirmed in-the-wild exploitation is documented here.
What to do
- Upgrade Apache OpenMeetings to a version later than 5.0.0 that contains the fix; the record does not name the fixed release, so confirm with the vendor advisory.
- Restrict network access to the NetTest web service and other OpenMeetings endpoints to trusted networks or VPN where possible.
- Place the service behind a reverse proxy or WAF with rate limiting and request size limits to blunt volumetric abuse.
- Monitor and cap resource consumption (threads, connections, memory) for the OpenMeetings process to limit blast radius.
- If the NetTest endpoint is not needed, disable or block it at the perimeter.
Detection
- Alert on abnormal request volume or connection spikes against the NetTest endpoint in web server or proxy logs.
- Monitor OpenMeetings process CPU, memory and thread counts for sustained saturation or restarts.
- Watch for repeated requests from single source IPs or unusual user agents hitting the NetTest path.
- Correlate service unavailability events with concurrent traffic patterns to the OpenMeetings host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-13951 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13951), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.