CVE-2025-48057
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
- EPSS probability
- 0.44%
- CWE
- CWE-296
- Published
- 2025-05-27
- Last modified
- 2026-03-13
Affected products
- Icinga icinga2
- Icinga icinga2
- Icinga icinga2
Weakness type
Related vulnerabilities
- CVE-2026-73542 — Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle...
- CVE-2026-24066 — Slate Digital Connect macOS XPC certificate validation privilege escalation
- CVE-2026-42789 — Non-CA certificate accepted as intermediate issuer in public_key path validation
- CVE-2025-10539 — Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
- CVE-2026-33779 — Junos OS: SRX Series: Insufficient certificate verification for device to SD cloud communication
- CVE-2026-27134 — Strimzi: All CAs from a custom CA chain consisting of multiple CAs are trusted for mTLS user autentication
- CVE-2026-27133 — Strimzi All CAs from CA chain will be trusted in Kafka Connect and Kafka MirrorMaker 2 target clusters
- CVE-2025-22459 — Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before...