CVE-2024-49369

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects with the client_cn attribute set). This vulnerability has been fixed in v2.14.3, v2.13.10, v2.12.11, and v2.11.12.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GitHub_MCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
icingaicinga
2.4.0 ≤
𝑥
< 2.11.12
icingaicinga
2.12.0 ≤
𝑥
< 2.12.11
icingaicinga
2.13.0 ≤
𝑥
< 2.13.10
icingaicinga
2.14.0 ≤
𝑥
< 2.14.3
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
icinga2
bullseye
vulnerable
bullseye (security)
2.12.3-1+deb11u1
fixed
bookworm
2.13.6-2+deb12u2
fixed
trixie
2.14.6-1
fixed
forky
2.15.1-1
fixed
sid
2.15.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icinga2
questing
not-affected
plucky
not-affected
oracular
ignored
noble
needs-triage
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage