PT-2025-22986 · Icinga 2+4 · Icinga 2+4

Yhabteab

·

Published

2025-05-27

·

Updated

2025-12-05

·

CVE-2025-48057

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Icinga 2 versions prior to 2.12.12 Icinga 2 versions prior to 2.13.12 Icinga 2 versions prior to 2.14.6
Description The issue affects Icinga 2, a monitoring system that checks network resource availability and generates performance data. It allows an attacker to obtain a valid certificate by tricking the VerifyCertificate() function into treating malicious certificates as valid. This occurs when Icinga 2 is built with OpenSSL older than version 1.1.0, such as on RHEL 7 or Amazon Linux 2. The attacker can then use the valid certificate to impersonate trusted nodes.
Recommendations For versions prior to 2.12.12, update to version 2.12.12 or later. For versions prior to 2.13.12, update to version 2.13.12 or later. For versions prior to 2.14.6, update to version 2.14.6 or later. As a temporary workaround, consider checking the OpenSSL version with icinga2 --version | grep OpenSSL and updating Icinga 2 if affected.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14018
CVE-2025-48057
GHSA-7VCF-F5V9-3WR6
OPENSUSE-SU-2025:15180-1
SUSE-SU-2025:02783-1
SUSE-SU-2025_02783-1

Affected Products

Alt Linux
Debian
Icinga 2
Openssl
Suse