CVE-2025-48057

EUVD-2025-28141
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.08%
Affected Products (NVD)
VendorProductVersion
icingaicinga
𝑥
< 2.12.12
icingaicinga
2.13.0 ≤
𝑥
< 2.13.12
icingaicinga
2.14.0 ≤
𝑥
< 2.14.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
icinga2
bookworm
ignored
bullseye
ignored
forky
2.16.5-1
fixed
sid
2.16.5-1
fixed
trixie
2.14.6-1
fixed
trixie (security)
2.14.6-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icinga2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
not-affected
xenial
needs-triage