Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6.
The VerifyCertificate() function contains a flaw (CWE-296 — improper verification of certificate chain), which allows a malicious certificate request to be treated as a renewal of an existing, trusted certificate. An attacker sends a crafted certificate request that passes verification despite lacking authorization to issue it. The problem occurs only when Icinga 2 is compiled with OpenSSL library version older than 1.1.0. The attacker does not need authentication — the vulnerability is remotely accessible without any user interaction.
An attacker obtains a valid certificate allowing impersonation of trusted nodes in the Icinga 2 infrastructure, which can lead to takeover of communication between nodes, injection of false monitoring data, and further lateral movement in the network.
Icinga 2 should be updated to version 2.12.12, 2.13.12, or 2.14.6, in which the vulnerability has been removed. Additionally, it is recommended to ensure that Icinga 2 is built and run with OpenSSL version 1.1.0 or newer, which eliminates the condition for the vulnerability to occur.
Icinga 2 in versions prior to 2.12.12, 2.13.12, and 2.14.6, compiled with OpenSSL version older than 1.1.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XIcinga
APPIcinga< 2.12.122.13.0 – 2.13.12 (excl.)2.14.0 – 2.14.6 (excl.)
Related vulnerabilities
Icinga 2: błędna walidacja certyfikatów TLS umożliwia podszywanie się pod węzły klastra i użytkowników API
Icinga 2 — automatyczne odnawianie unieważnionych certyfikatów (pominięcie CRL)
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions prov...
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating...
Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's ...