CRITICAL🇵🇱 Wersja polska

CVE-2025-48057

CVSS 9.3v4.0pub. 2025-05-27upd. 2025-12-05

Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6.

🤖 AI Analysis
How it works

The VerifyCertificate() function contains a flaw (CWE-296 — improper verification of certificate chain), which allows a malicious certificate request to be treated as a renewal of an existing, trusted certificate. An attacker sends a crafted certificate request that passes verification despite lacking authorization to issue it. The problem occurs only when Icinga 2 is compiled with OpenSSL library version older than 1.1.0. The attacker does not need authentication — the vulnerability is remotely accessible without any user interaction.

Impact

An attacker obtains a valid certificate allowing impersonation of trusted nodes in the Icinga 2 infrastructure, which can lead to takeover of communication between nodes, injection of false monitoring data, and further lateral movement in the network.

Mitigation & patch

Icinga 2 should be updated to version 2.12.12, 2.13.12, or 2.14.6, in which the vulnerability has been removed. Additionally, it is recommended to ensure that Icinga 2 is built and run with OpenSSL version 1.1.0 or newer, which eliminates the condition for the vulnerability to occur.

Who is affected

Icinga 2 in versions prior to 2.12.12, 2.13.12, and 2.14.6, compiled with OpenSSL version older than 1.1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Icinga

    APP
    Icinga
    < 2.12.122.13.0 – 2.13.12 (excl.)2.14.0 – 2.14.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-49369CRITICAL9.8PL ✓same product

Icinga 2: błędna walidacja certyfikatów TLS umożliwia podszywanie się pod węzły klastra i użytkowników API

CVE-2020-29663CRITICAL9.1PL ✓same product

Icinga 2 — automatyczne odnawianie unieważnionych certyfikatów (pominięcie CRL)

CVE-2025-61907HIGH7.1same product

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions prov...

CVE-2025-61908HIGH7.1same product

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating...

CVE-2024-24820HIGH8.3same product

Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's ...