Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28141 | Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 05 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icinga
Icinga icinga |
|
| CPEs | cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Icinga
Icinga icinga |
|
| Metrics |
cvssV3_1
|
Tue, 27 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal of an already existing certificate, resulting in the attacker obtaining a valid certificate that can be used to impersonate trusted nodes. This only occurs when Icinga 2 is built with OpenSSL older than version 1.1.0. This issue has been patched in versions 2.12.12, 2.13.12, and 2.14.6. | |
| Title | Icinga 2 certificate renewal might incorrectly renew an invalid certificate | |
| Weaknesses | CWE-296 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-27T18:27:57.002Z
Reserved: 2025-05-15T16:06:40.940Z
Link: CVE-2025-48057
Updated: 2025-05-27T18:27:50.828Z
Status : Analyzed
Published: 2025-05-27T17:15:26.387
Modified: 2025-12-05T00:12:22.747
Link: CVE-2025-48057
No data.
OpenCVE Enrichment
No data.
EUVD