PT-2025-22986 · Icinga 2+4 · Icinga 2+4

Yhabteab

·

Publicado

2025-05-27

·

Atualizado

2025-12-05

·

CVE-2025-48057

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Icinga 2 versions prior to 2.12.12 Icinga 2 versions prior to 2.13.12 Icinga 2 versions prior to 2.14.6
Description The issue affects Icinga 2, a monitoring system that checks network resource availability and generates performance data. It allows an attacker to obtain a valid certificate by tricking the VerifyCertificate() function into treating malicious certificates as valid. This occurs when Icinga 2 is built with OpenSSL older than version 1.1.0, such as on RHEL 7 or Amazon Linux 2. The attacker can then use the valid certificate to impersonate trusted nodes.
Recommendations For versions prior to 2.12.12, update to version 2.12.12 or later. For versions prior to 2.13.12, update to version 2.13.12 or later. For versions prior to 2.14.6, update to version 2.14.6 or later. As a temporary workaround, consider checking the OpenSSL version with icinga2 --version | grep OpenSSL and updating Icinga 2 if affected.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-14018
CVE-2025-48057
GHSA-7VCF-F5V9-3WR6
OPENSUSE-SU-2025:15180-1
SUSE-SU-2025:02783-1
SUSE-SU-2025_02783-1

Produtos afetados

Alt Linux
Debian
Icinga 2
Openssl
Suse