- Description
- Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-296
- Hype score
- Not currently trending
🚨 CVE-2025-48057 ⚠️🔴 CRITICAL (9.3) 🏢 Icinga - icinga2 🏗️ >= 2.14.0, < 2.14.6 🔗 https://t.co/B2NmxK93R9 🔗 https://t.co/KZIV8j3TLT 🔗 https://t.co/5amcTet5w4 🔗 https://t.co/g3K00vKMz2 🔗 https://t.co/EO7b5mnoGn 🔗 https://t.co/hNeG7TT64O #Cyb
@cybercronai
29 May 2025
30 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-48057 Certificate Validation Bypass in Icinga 2 with OpenSSL Versions Below 1.1.0 https://t.co/U3Lr1Xs5Th
@VulmonFeeds
27 May 2025
57 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-48057 Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to … https://t.co/8RFNCBoL5d
@CVEnew
27 May 2025
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-48057: CRITICAL] Monitor network resources with Icinga 2, a system for cyber defense, but beware prior versions can be tricked by attackers for certificate impersonation. Update to 2.12.12, 2.13.12...#cve,CVE-2025-48057,#cybersecurity https://t.co/ZYf4mkkBpT https://t.c
@CveFindCom
27 May 2025
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes